A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user.
2020-09-04T12:15:10.543
2024-11-21T05:36:39.737
Modified
CVSSv3.1: 4.9 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | arubanetworks | analytics_and_location_engine | < 2.1.0.3 | Yes |
Application | arubanetworks | analytics_and_location_engine | 2.0.0.0 | Yes |