VYPR
High severity7.2NVD Advisory· Published Jan 15, 2021· Updated Jun 17, 2026

CVE-2020-24638

CVE-2020-24638

Description

Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root on the underlying host operating system.

Affected products

3
  • cpe:2.3:a:arubanetworks:airwave_glass:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:arubanetworks:airwave_glass:*:*:*:*:*:*:*:*range: <1.3.3
    • (no CPE)range: <1.3.3
  • Airwave/Airwave Glassdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.