CVE-2023-30509

Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:*

History

22 Jan 2025, 21:15

Type Values Removed Values Added
References (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-007.txt - () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-007.txt -

07 Jul 2023, 15:15

Type Values Removed Values Added
References
  • {'url': 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-0007.txt', 'name': 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-0007.txt', 'tags': ['Broken Link', 'Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-007.txt -

25 May 2023, 15:42

Type Values Removed Values Added
First Time Arubanetworks
Arubanetworks edgeconnect Enterprise
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-0007.txt - (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-0007.txt - Broken Link, Vendor Advisory
CPE cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:*
CWE CWE-22

16 May 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-16 19:15

Updated : 2025-01-22 21:15


NVD link : CVE-2023-30509

Mitre link : CVE-2023-30509


JSON object : View

Products Affected

arubanetworks

  • edgeconnect_enterprise
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')