CVE-2021-26969
CVE-2021-26969
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
05 Mar 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML entities a vulnerability exists in the web-based management interface of AirWave. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.
Affected products
n/a · Aruba AirWave Management PlatformWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →