5.5
CVSSv2

CVE-2021-26969

Published: 05/03/2021 Updated: 11/03/2021
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

A remote authenticated authenticated xml external entity (xxe) vulnerability exists in Aruba AirWave Management Platform version(s): before 8.2.12.0. Due to improper restrictions on XML entities a vulnerability exists in the web-based management interface of AirWave. A successful exploit could allow an authenticated malicious user to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arubanetworks airwave