CVE Vulnerabilities

CVE-2020-7119

Published: Sep 04, 2020 | Modified: Sep 09, 2020
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user.

Affected Software

Name Vendor Start Version End Version
Analytics_and_location_engine Arubanetworks 2.1.0.0 (including) 2.1.0.3 (excluding)
Analytics_and_location_engine Arubanetworks 2.0.0.0 (including) 2.0.0.0 (including)

References