Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.
A product defines a set of insecure permissions that are inherited by objects that are created by the program.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Arubaos | Arubanetworks | 6.5.4.0 (including) | 8.10.0.21 (excluding) |
| Arubaos | Arubanetworks | 8.11.0.0 (including) | 8.13.1.1 (excluding) |
| Arubaos | Arubanetworks | 10.3.0.0 (including) | 10.4.1.10 (excluding) |
| Arubaos | Arubanetworks | 10.5.0.0 (including) | 10.7.2.2 (excluding) |