Show filters
54 Total Results
Displaying 1-10 of 54
Sort by:
Attacker Value
Unknown

CVE-2024-54008

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host.
0
Attacker Value
Unknown

CVE-2023-4896

Disclosure Date: October 17, 2023 (last updated October 25, 2023)
A vulnerability exists which allows an authenticated attacker to access sensitive information on the AirWave Management Platform web-based management interface. Successful exploitation allows the attacker to gain access to some data that could be further exploited to laterally access devices managed and monitored by the AirWave server.
Attacker Value
Unknown

CVE-2015-2202

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.
Attacker Value
Unknown

CVE-2015-2201

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.
Attacker Value
Unknown

CVE-2015-1391

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.
Attacker Value
Unknown

CVE-2015-1390

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.
Attacker Value
Unknown

CVE-2022-37918

Disclosure Date: December 08, 2022 (last updated November 08, 2023)
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at a higher effective level in Aruba AirWave Management Platform version(s): 8.2.15.0 and below.
Attacker Value
Unknown

CVE-2022-37917

Disclosure Date: December 08, 2022 (last updated November 08, 2023)
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at a higher effective level in Aruba AirWave Management Platform version(s): 8.2.15.0 and below.
Attacker Value
Unknown

CVE-2022-37916

Disclosure Date: December 08, 2022 (last updated November 08, 2023)
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at a higher effective level in Aruba AirWave Management Platform version(s): 8.2.15.0 and below.
Attacker Value
Unknown

CVE-2021-37715

Disclosure Date: August 26, 2021 (last updated February 23, 2025)
A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.13.0. Aruba has released upgrades for the Aruba AirWave Management Platform that address this security vulnerability.