CVE-2019-5326
Severity CVSS v4.0:
Pending analysis
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
27/02/2020
Last modified:
03/03/2020
Description
An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:arubanetworks:airwave:*:*:*:*:*:*:*:* | 8.0.0 (including) | 8.2.10.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page