CVE-2019-5323
HIGHAruba AirWave 8.0.0-8.2.10.0 - Authenticated Command Injection via Input Field
Title source: llmDescription
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-002.txt
Scores
CVSS v3
7.2
EPSS
0.0112
EPSS Percentile
78.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (1)
arubanetworks/airwave
8.0.0 - 8.2.10.1
Published
Feb 27, 2020
Tracked Since
Feb 18, 2026