High severity7.2NVD Advisory· Published Feb 27, 2020· Updated Jun 17, 2026
CVE-2019-5323
CVE-2019-5323
Description
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.
Affected products
3cpe:2.3:a:arubanetworks:airwave:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:arubanetworks:airwave:*:*:*:*:*:*:*:*range: >=8.0.0,<8.2.10.1
- (no CPE)
- AirWave/AirWavedescription
Patches
Vulnerability mechanics
References
1- www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-002.txtnvdVendor Advisory
News mentions
0No linked articles in our index yet.