CVE-2019-5315
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
13/09/2019
Last modified:
16/09/2019
Description
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. This vulnerability only affects ArubaOS 8.x.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* | 8.0.0.0 (including) | 8.3.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page