VYPR
Medium severity6.1NVD Advisory· Published Sep 13, 2019· Updated Jun 17, 2026

CVE-2019-5314

CVE-2019-5314

Description

Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.

Affected products

3
  • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*range: <6.4.4.20
    • (no CPE)
  • Aruba/ArubaOSdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.