CVE-2019-5323: Command Injection
Published Feb 27, 2020
·Updated
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.
Affected Software
1 affected component
Arubanetworks Airwave>=8.0.0<8.2.10.1
Event History
Feb 27, 2020
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-5323?
CVE-2019-5323 is a command injection vulnerability present in the AirWave application.
2
How does CVE-2019-5323 impact AirWave?
CVE-2019-5323 allows an attacker to execute arbitrary commands on the host if certain conditions are met.
3
What is the severity of CVE-2019-5323?
CVE-2019-5323 has a severity rating of 7.2 (high).
4
Which version of AirWave is affected by CVE-2019-5323?
AirWave versions 8.0.0 to 8.2.10.1 are affected by CVE-2019-5323.
5
How can I fix CVE-2019-5323?
To fix CVE-2019-5323, it is recommended to upgrade AirWave to a version that includes a fix for the vulnerability.