CVE-2019-5322
Published on: 02/12/2020 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:59 PM UTC
Certain versions of 2530 10/100 Port from Arubanetworks contain the following vulnerability:
A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007 and 16.10.* before 16.10.0003. The vulnerability allows an attacker to retrieve sensitive system information. This attack can be carried out without user authentication under very specific conditions.
- CVE-2019-5322 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Vendor Advisory www.arubanetworks.com text/plain |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
- cpe:2.3:h:arubanetworks:2530_10/100_port:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2530_10/100_port_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2530_10\/100_port:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2530_10\/100_port:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2530_10\/100_port_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2530_10\/100_port_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2530_with_gigt_port:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2530_with_gigt_port:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2530_with_gigt_port_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2530_with_gigt_port_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2540:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2540:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2920:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2920:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2930:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2930:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:3810:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:3810:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:3810_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:3810_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:5400r:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:5400r:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:5400r_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:5400r_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE