PT-2023-29598 · Aruba · Airwave
Xiaoc
·
Published
2023-11-14
·
Updated
2023-11-21
·
CVE-2023-45618
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
AirWave (affected versions not specified)
Description
The issue concerns arbitrary file deletion vulnerabilities in the AirWave client service, which is accessed through PAPI, Aruba's access point management protocol. Successful exploitation of these vulnerabilities can lead to the deletion of arbitrary files on the underlying operating system. This could potentially interrupt normal operation and impact the integrity of the access point.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Airwave