← Back

CVE-2018-7084

nvd nist
Published: May 10, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.1

Affected (5)

1 product
Aruba Instant
1 product
Scalance W1750d Firmware
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Arubanetworks
From 4.0 to 4.2.4.12
From 6.5.0 to 6.5.4.11
From 8.3.0 to 8.3.0.6
From 8.4.0 to 8.4.0.1
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.4.0.1
Running on/withPlatform Versions
Siemens
Scalance W1750d
All versions

References (6)

Source: security-alert@hpe.com
Broken LinkThird Party AdvisoryVDB Entry
Source: security-alert@hpe.com
Third Party Advisory
Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.