CVE-2014-8368: Critical severity aruba networks airwave vulnerability
Published Nov 25, 2014
·Updated
The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors.
Affected Software
2 affected components
Arubanetworks Airwave>=7.7.0<7.7.14
Arubanetworks Airwave>=8.0.0<8.0.5
Event History
Nov 25, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8368?
CVE-2014-8368 has a high severity level due to the potential for remote authenticated users to escalate privileges and execute arbitrary commands.
2
How do I fix CVE-2014-8368?
To mitigate CVE-2014-8368, upgrade Aruba Networks AirWave to version 7.7.14 or 8.0.5 or later.
3
Which versions of Aruba Networks AirWave are affected by CVE-2014-8368?
CVE-2014-8368 affects Aruba Networks AirWave versions prior to 7.7.14 and all versions before 8.0.5.
4
Who can exploit CVE-2014-8368?
CVE-2014-8368 can be exploited by remote authenticated users with access to the web interface.
5
What types of attacks can be executed due to CVE-2014-8368?
CVE-2014-8368 allows attackers to gain elevated privileges and execute arbitrary commands on the affected systems.