CVE-2019-5401
Last modified
CVE-2019-5401 is a vulnerability of currently unknown severity. A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). But admin privileges are required to configure these fields thereby reducing the likelihood of exploit. HPE Aruba has provided firmware updates to resolve the vulnerability in HP 2910-48G al Switch. Please update to W.15.14.0017.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Hp2910al-48g Firmware | w.15.14.00.16 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5401?
How severe is CVE-2019-5401?
How do I fix CVE-2019-5401?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5395A remote arbitrary file upload vulnerability was discovered …
- CVE-2019-5396A remote authentication bypass vulnerability was discovered …
- CVE-2019-5397A remote bypass of security restrictions vulnerability was d…
- CVE-2019-5398A remote multiple multiple cross-site vulnerability was disc…
- CVE-2019-5399A remote gain authorized access vulnerability was discovered…
- CVE-2019-5400A remote session reuse vulnerability was discovered in HPE 3…
- CVE-2019-5402A remote authorization bypass vulnerability was discovered i…
- CVE-2019-5403A remote multiple cross-site scripting vulnerability was dis…
- CVE-2019-5404A remote script injection vulnerability was discovered in HP…
- CVE-2019-5405A remote authorization bypass vulnerability was discovered i…
- CVE-2019-5406A remote session reuse vulnerability was discovered in HPE 3…
- CVE-2019-5407A remote information disclosure vulnerability was discovered…
Are you affected by CVE-2019-5401?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
