First published: Fri Mar 05 2021(Updated: )
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an authenticated remote attacker to improperly access and modify devices and management user details. A successful exploit would consist of an attacker using a lower privileged account to change management user or device details. This could allow the attacker to escalate privileges and/or change network details that they should not have access to.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Airwave | <8.2.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26964 is a remote authentication restriction bypass vulnerability discovered in Aruba AirWave Management Platform.
The severity of CVE-2021-26964 is high with a CVSS score of 7.1.
Aruba AirWave Management Platform versions prior to 8.2.12.0 are affected by CVE-2021-26964.
An authenticated remote attacker can exploit CVE-2021-26964 to improperly access and modify devices and management interfaces.
Yes, upgrading to Aruba AirWave Management Platform 8.2.12.0 or later will fix CVE-2021-26964.