CVE-2019-5326

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
27/02/2020
Last modified:
03/03/2020

Description

An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:airwave:*:*:*:*:*:*:*:* 8.0.0 (including) 8.2.10.1 (excluding)


References to Advisories, Solutions, and Tools