Description
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
Product status
10.17.0000 (semver)
10.16.0000 (semver)
10.13.0000 (semver)
10.10.0000 (semver)
Credits
This vulnerability was discovered by Christopher Simmelink through HPE Aruba Networking’s Bug Bounty program.
References
support.hpe.com/...y?docId=hpesbnw05027en_us&docLocale=en_US