cisagov / vulnrichment

A repo to conduct vulnerability enrichment.
Creative Commons Zero v1.0 Universal
406 stars 29 forks source link

Aruba CVE CVE-2024-31468 CPE does not express the different versions impacted properly #27

Closed patrickmgarrity closed 1 month ago

patrickmgarrity commented 1 month ago

Aruba CVE CVE-2024-31468 CPE does not express the different versions impacted properly. I would recommend checking other CVE's from this CNA to validate if the problem is broader across all CVEs.

Found here: https://github.com/cisagov/vulnrichment/blob/adf3de55261c34aa178ae9660e4fb8215dcb4f9d/2024/31xxx/CVE-2024-31468.json#L104

Example of another Aruba CVE expressing multiple versions: https://nvd.nist.gov/vuln/detail/cve-2023-22752

The information is clarified in their product advisory...

Affected Products

HPE Aruba Networking

Affected Software Versions:

The following software versions that are End of Maintenance are affected by these vulnerabilities and are not addressed by this advisory:

jwoytek-cisa commented 1 month ago

@patrickmgarrity Thank you! I've passed this up to our analysts to evaluate. We may not have been supporting arrays of version specifiers when this was first published, which restricted the way we could represent versions in this arrangement. We will make needed updates upstream and will republish. I will hold this open until that is complete.