Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.
2023-03-01T08:15:13.367
2024-11-21T07:45:22.497
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | arubanetworks | sd-wan | ≤ 8.7.0.0-2.3.0.8 | Yes |
Operating System | arubanetworks | arubaos | ≤ 8.6.0.19 | Yes |
Operating System | arubanetworks | arubaos | ≤ 8.10.0.4 | Yes |
Operating System | arubanetworks | arubaos | ≤ 10.3.1.0 | Yes |