Описание
An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.
Уязвимые конфигурации
Конфигурация 1Версия от 8.10.0.0 (включая) до 8.10.0.19 (исключая)Версия от 8.12.0.0 (включая) до 8.12.0.6 (исключая)Версия от 8.13.0.0 (включая) до 8.13.1.0 (исключая)Версия от 10.4.0.0 (включая) до 10.4.1.9 (исключая)Версия от 10.7.0.0 (включая) до 10.7.2.1 (исключая)
Одно из
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
EPSS
Процентиль: 20%
0.00065
Низкий
7.2 High
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 7.2
github
4 месяца назад
An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.
EPSS
Процентиль: 20%
0.00065
Низкий
7.2 High
CVSS3
Дефекты
CWE-434