CVE-2018-16417: Command Injection
Published Oct 30, 2019
·Updated
Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.
Affected Software
6 affected components
Arubanetworks Instant>=4.0.0.0<4.2.4.12
Arubanetworks Instant>=6.5.0.0<6.5.4.11
Arubanetworks Instant>=8.3.0.0<8.3.0.6
Arubanetworks Instant>=8.4.0.0<8.4.0.1
Siemens W1750d Firmware<8.4.0.1
Siemens W1750d
Event History
Oct 30, 2019
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16417?
The severity of CVE-2018-16417 is high, with a severity value of 7.5.
2
What is the affected software of CVE-2018-16417?
The affected software of CVE-2018-16417 is Aruba Instant versions 4.x, 6.5.x, 8.3.x, and 8.4.x.
3
How does CVE-2018-16417 allow command injection?
CVE-2018-16417 allows command injection through a vulnerability in Aruba Instant.
4
Are Siemens W1750d devices vulnerable to CVE-2018-16417?
Siemens W1750d devices are not vulnerable to CVE-2018-16417.
5
Where can I find more information about CVE-2018-16417?
You can find more information about CVE-2018-16417 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/108374), [Siemens Product Cert](https://cert-portal.siemens.com/productcert/pdf/ssa-549547.pdf), [Anquanke](https://www.anquanke.com/vul/id/1652568).