ZeroHour

CVE-2020-24641

CVSS 3.1
7.5 high
EPSS
1%p72
Published
()
Modified
Description

In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be used to perform an authentication bypass and ultimately gain administrative access on the web administrative interface.

Vendors
arubanetworks
Products
airwave glass
Weakness
CWE-287, CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.