Vulnerability CVE-2019-5326


Published: 2020-02-27

Description:
An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component.

Type:

CWE-502

(Deserialization of Untrusted Data)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Arubanetworks -> Airwave 

 References:
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-002.txt

Copyright 2024, cxsecurity.com

 

Back to Top