CVE-2019-5322
Last modified
CVE-2019-5322 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007 and 16.10.* before 16.10.0003. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007 and 16.10.* before 16.10.0003. The vulnerability allows an attacker to retrieve sensitive system information. This attack can be carried out without user authentication under very specific conditions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | 5400r Firmware | >= 16.08.0, < 16.08.0009 |
| Arubanetworks | 5400r Firmware | >= 16.09.0, < 16.09.0007 |
| Arubanetworks | 5400r Firmware | >= 16.10.0, < 16.10.0003 |
| Arubanetworks | 3810 Firmware | >= 16.08.0, < 16.08.0009 |
| Arubanetworks | 3810 Firmware | >= 16.09.0, < 16.09.0007 |
| Arubanetworks | 3810 Firmware | >= 16.10.0, < 16.10.0003 |
| Arubanetworks | 2920 Firmware | >= 16.08.0, < 16.08.0009 |
| Arubanetworks | 2920 Firmware | >= 16.09.0, < 16.09.0007 |
| Arubanetworks | 2920 Firmware | >= 16.10.0, < 16.10.0003 |
| Arubanetworks | 2930 Firmware | >= 16.08.0, < 16.08.0009 |
| Arubanetworks | 2930 Firmware | >= 16.09.0, < 16.09.0007 |
| Arubanetworks | 2930 Firmware | >= 16.10.0, < 16.10.0003 |
| Arubanetworks | 2530 With Gigt Port Firmware | >= 16.08.0, < 16.08.0009 |
| Arubanetworks | 2530 With Gigt Port Firmware | >= 16.09.0, < 16.09.0007 |
| Arubanetworks | 2530 With Gigt Port Firmware | >= 16.10.0, < 16.10.0003 |
| Arubanetworks | 2530 10\/100 Port Firmware | >= 16.08.0, < 16.08.0009 |
| Arubanetworks | 2530 10\/100 Port Firmware | >= 16.09.0, < 16.09.0007 |
| Arubanetworks | 2530 10\/100 Port Firmware | >= 16.10.0, < 16.10.0003 |
| Arubanetworks | 2540 Firmware | >= 16.08.0, < 16.08.0009 |
| Arubanetworks | 2540 Firmware | >= 16.09.0, < 16.09.0007 |
| Arubanetworks | 2540 Firmware | >= 16.10.0, < 16.10.0003 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5322?
How severe is CVE-2019-5322?
How do I fix CVE-2019-5322?
Are you affected by CVE-2019-5322?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
