CVE-2020-24638: Command Injection
Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root on the underlying host operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24638?
CVE-2020-24638 is considered a critical vulnerability due to its potential for authenticated remote command execution.
How do I fix CVE-2020-24638?
To fix CVE-2020-24638, upgrade to Airwave Glass version 1.3.3 or later.
Who is affected by CVE-2020-24638?
CVE-2020-24638 affects users with glassadmin privileges on versions of Airwave Glass prior to 1.3.3.
What type of attack is CVE-2020-24638?
CVE-2020-24638 allows for remote command execution where an attacker can execute arbitrary code on the host system.
What can be exploited due to CVE-2020-24638?
CVE-2020-24638 can be exploited to gain root access on the underlying operating system by authorized users.