PT-2022-24148 · Aruba · Aruba Airwave Management Platform

Colton Bachman

·

Published

2022-12-08

·

Updated

2022-12-12

·

CVE-2022-37916

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Aruba AirWave Management Platform versions 8.2.15.0 and below
Description Vulnerabilities in the AirWave Management Platform web-based management interface exist, which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at a higher effective level.
Recommendations For versions 8.2.15.0 and below, update to a version above 8.2.15.0 to resolve the issue. As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-37916

Affected Products

Aruba Airwave Management Platform