CVE-2019-5326Deserialization of Untrusted Data in Airwave

Severity
7.2HIGHNVD
EPSS
2.5%
top 14.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27
Latest updateMay 24

Description

An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

NVDarubanetworks/airwave8.0.08.2.10.1

🔴Vulnerability Details

2
GHSA
GHSA-x8jm-4c7g-vg4f: An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP plat2022-05-24
CVEList
CVE-2019-5326: An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP plat2020-02-27
CVE-2019-5326 — Deserialization of Untrusted Data | cvebase