Aller au contenu

Fiche vulnérabilité

CVE-2025-27084 : faille moyenne arubanetworks arubaos (CVSS 6.1)

Description

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface.

En bref

Sévérité
Moyenne (CVSS 6.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
8 avr. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • arubanetworks arubaos

Références

Rechercher une autre vulnérabilité dans la base CVE