CVE-2021-26961: CSRF
A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system. A successful exploit would consist of an attacker persuading an authorized user to follow a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-26961.
What is the severity of CVE-2021-26961?
The severity of CVE-2021-26961 is high (8.8).
What is the affected software for CVE-2021-26961?
The affected software for CVE-2021-26961 is Aruba AirWave Management Platform versions prior to 8.2.12.0.
What is a remote unauthenticated cross-site request forgery (CSRF) vulnerability?
A remote unauthenticated cross-site request forgery (CSRF) vulnerability allows an attacker to perform unauthorized actions on behalf of a user without their knowledge or consent.
How can I fix CVE-2021-26961?
To fix CVE-2021-26961, you should update Aruba AirWave Management Platform to version 8.2.12.0 or later.