CVE-2020-7119
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/09/2020
Last modified:
09/09/2020
Description
A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user.
Impact
Base Score 3.x
4.90
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:arubanetworks:analytics_and_location_engine:*:*:*:*:*:*:*:* | 2.1.0.0 (including) | 2.1.0.3 (excluding) |
| cpe:2.3:a:arubanetworks:analytics_and_location_engine:2.0.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



