Authenticated Command Injection Vulnerability in HPE Aruba Networking Management Software (AirWave) CLI
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying operating system.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H