CVE-2018-16417
HIGHAruba Instant 4.x < 4.2.4.12, 6.5.x < 6.5.4.11, 8.3.x < 8.3.0.6, 8.4.x < 8.4.0.1 - Command Injection
Title source: llmDescription
Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-001.txt
Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-549547.pdf
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/108374
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://www.us-cert.gov/ics/advisories/ICSA-19-134-07
Third Party Advisory x_refsource_misc
https://www.anquanke.com/vul/id/1652568
Scores
CVSS v3
7.5
EPSS
0.0334
EPSS Percentile
87.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-77
Status
published
Products (2)
arubanetworks/instant
4.0.0.0 - 4.2.4.12
siemens/w1750d_firmware
< 8.4.0.1
Published
Oct 30, 2019
Tracked Since
Feb 18, 2026