CVE-2025-23057

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 28, 2025

Summary

CVE-2025-23057 is a newly disclosed vulnerability that affects the web management interface of HPE Aruba Networking Fabric Composer. This issue enables authenticated remote attackers to execute stored cross-site scripting (XSS) attacks. Successful exploitation of this vulnerability allows attackers to inject arbitrary script code into a victim's web browser, potentially leading to unauthorized access, data theft, or other malicious activities within the compromised interface. It is crucial for organizations using the affected product to apply the necessary patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share