CVE-2025-23056
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-23056 is a newly identified vulnerability that affects the web management interface of HPE Aruba Networking Fabric Composer. An authenticated attacker can exploit this issue to execute stored cross-site scripting (XSS) attacks. By injecting malicious code into the interface, a threat actor could gain unauthorized access to a victim's web browser and run arbitrary scripts. This vulnerability poses a significant risk to organizations that use HPE Aruba Networking Fabric Composer, as it can lead to unintended data exposure or theft of sensitive information. It is essential that affected organizations apply the necessary patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.