CVE-2019-5323
Last modified
CVE-2019-5323 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. EPSS estimates a 2.56% chance of exploitation in the next 30 days.
Description
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Airwave | >= 8.0.0, < 8.2.10.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5323?
How severe is CVE-2019-5323?
How do I fix CVE-2019-5323?
Are you affected by CVE-2019-5323?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
