First published: Fri Jan 15 2021(Updated: )
Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root on the underlying host operating system.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Aruba AirWave Glass | <1.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24638 is considered a critical vulnerability due to its potential for authenticated remote command execution.
To fix CVE-2020-24638, upgrade to Airwave Glass version 1.3.3 or later.
CVE-2020-24638 affects users with glassadmin privileges on versions of Airwave Glass prior to 1.3.3.
CVE-2020-24638 allows for remote command execution where an attacker can execute arbitrary code on the host system.
CVE-2020-24638 can be exploited to gain root access on the underlying operating system by authorized users.