CVE-2019-5315

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
13/09/2019
Last modified:
16/09/2019

Description

A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. This vulnerability only affects ArubaOS 8.x.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 8.0.0.0 (including) 8.3.0.0 (excluding)


References to Advisories, Solutions, and Tools