CVE-2016-2031: Input Validation
Published Jan 31, 2020
·Updated
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary code.
Affected Software
6 affected components
Arubanetworks Airwave<8.2.0.0
Arubanetworks Aruba Instant<4.1.3.0
Arubanetworks Aruba Instant=4.2.3.1
Arubanetworks Arubaos
Siemens Scalance W1750d Firmware
Siemens SCALANCE W1750D
Event History
Jan 31, 2020
CVE Published
via MITRE·07:33 PM
Data Sourced
via MITRE·07:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2031?
The severity of CVE-2016-2031 is critical.
2
Which software versions are affected by CVE-2016-2031?
Aruba Instate versions before 4.1.3.0 and 4.2.3.1 are affected by CVE-2016-2031.
3
What is the CWE ID of CVE-2016-2031?
The CWE ID of CVE-2016-2031 is 20.
4
How can a malicious user exploit CVE-2016-2031?
A malicious user can exploit CVE-2016-2031 by bypassing security restrictions, obtaining sensitive information, and performing unauthorized actions.
5
Are Siemens Scalance W1750d devices vulnerable to CVE-2016-2031?
No, Siemens Scalance W1750d devices are not vulnerable to CVE-2016-2031.