CVE-2019-5326 — Deserialization of Untrusted Data in Airwave
Severity
7.2HIGHNVD
EPSS
2.5%
top 14.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27
Latest updateMay 24
Description
An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-x8jm-4c7g-vg4f: An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP plat↗2022-05-24
CVEList▶
CVE-2019-5326: An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP plat↗2020-02-27