VYPR
Medium severity4.9NVD Advisory· Published Sep 4, 2020· Updated Jun 17, 2026

CVE-2020-7119

CVE-2020-7119

Description

A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user.

Affected products

4
  • cpe:2.3:a:arubanetworks:analytics_and_location_engine:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:arubanetworks:analytics_and_location_engine:*:*:*:*:*:*:*:*range: >=2.1.0.0,<2.1.0.3
    • cpe:2.3:a:arubanetworks:analytics_and_location_engine:2.0.0.0:*:*:*:*:*:*:*
    • (no CPE)range: <=2.1.0.2
  • Aruba/Analytics and Location Engine (ALE) web management interfacedescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.