CVE Vulnerabilities

CVE-2023-22771

Insufficient Session Expiration

Published: Mar 01, 2023 | Modified: Nov 07, 2023
CVSS 3.x
2.4
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Arubaos Arubanetworks 8.6.0.0 (including) 8.6.0.19 (including)
Arubaos Arubanetworks 8.10.0.0 (including) 8.10.0.4 (including)
Arubaos Arubanetworks 10.3.0.0 (including) 10.3.1.0 (including)

Potential Mitigations

References