Database/Firmware, BMC & network fabric

ArubaOS-Switch web management interface: Unauthenticated stored cross-site scripting against the ArubaOS-Switch web UI
Impact
Unauthenticated stored cross-site scripting against the ArubaOS-Switch web UI. Stored XSS in a switch management interface is a credential-theft and config-change path aimed at your network operators: an attacker plants the payload without logging in, and it fires the next time an admin opens the page.
Who can reach it
Unauthenticated, remote to the switch's web management interface; the payload executes in an administrator's browser session.
What to do
ArubaOS-Switch firmware upgrade plus reload. Immediate mitigation is a config change: disable the web management interface and manage via SSH/CLI, which most datacenter operators should be doing anyway. Related ArubaOS issue: CVE-2023-35971.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.