Vulnerability Details CVE-2020-24638
Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root on the underlying host operating system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.027
EPSS Ranking 85.3%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 9.0
Products affected by CVE-2020-24638
-
cpe:2.3:a:arubanetworks:airwave_glass:-
-
cpe:2.3:a:arubanetworks:airwave_glass:1.2.1
-
cpe:2.3:a:arubanetworks:airwave_glass:1.3.0
-
cpe:2.3:a:arubanetworks:airwave_glass:1.3.1
-
cpe:2.3:a:arubanetworks:airwave_glass:1.3.2