PT-2017-16214 · Vmware · Vmware Airwatch Console

Published

2017-11-16

·

Updated

2017-12-04

·

CVE-2017-4931

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware AirWatch Console versions prior to 9.2.0
Description The issue allows an authenticated AWC user to add malicious data to an enrolled device's log files. Successful exploitation could result in an unsuspecting AWC user opening a CSV file that contains malicious content.
Recommendations For versions prior to 9.2.0, update to version 9.2.0 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-4931

Affected Products

Vmware Airwatch Console