"value":"A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to\u00a0conduct a stored cross-site scripting (XSS) attack against a\u00a0user of the interface. A successful exploit could\u00a0allow an attacker to execute arbitrary script code in a\u00a0victim's browser in the context of the affected interface."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"n/a"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Hewlett Packard Enterprise (HPE)",
"product":{
"product_data":[
{
"product_name":"Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"status":"affected",
"version":"- ArubaOS 10.4.x.x: 10.4.0.1 and below"
},
{
"status":"affected",
"version":"- ArubaOS 8.11.x.x: 8.11.1.0 and below"
},
{
"status":"affected",
"version":"- ArubaOS 8.10.x.x: 8.10.0.6 and below"