CVE-2016-2032

Published on: 01/31/2020 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:15 PM UTC

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Certain versions of Airwave Network Management from Arubanetworks contain the following vulnerability:

A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672

  • CVE-2016-2032 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.5 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH NONE NONE

CVSS2 Score: 5 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL NONE NONE

CVE References

Description Tags Link
Vendor Advisory
www.arubanetworks.com
text/plain
URL Logo MISC www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-005.txt
Vulnerabilities – Application Security – Google Third Party Advisory
www.google.com
text/html
URL Logo MISC www.google.com/about/appsecurity/research/
Aruba Authentication Bypass / Insecure Transport / Tons Of Issues ≈ Packet Storm Exploit
Third Party Advisory
VDB Entry
packetstormsecurity.com
text/html
URL Logo MISC packetstormsecurity.com/files/136997/Aruba-Authentication-Bypass-Insecure-Transport-Tons-Of-Issues.html
Full Disclosure: Aruba ArubaOS/Aruba Instant/AirWave Management - Multiple Vulnerabilities (CVE-2016-2031, CVE-2016-2032) Exploit
Mailing List
Third Party Advisory
seclists.org
text/html
URL Logo MISC seclists.org/fulldisclosure/2016/May/19

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationArubanetworksAirwave Network ManagementAllAllAllAll
ApplicationArubanetworksAirwave Network ManagementAllAllAllAll
Operating
System
ArubanetworksArubaosAllAllAllAll
Operating
System
ArubanetworksArubaosAllAllAllAll
ApplicationArubanetworksAruba InstantAllAllAllAll
ApplicationArubanetworksAruba Instant4.2.3.1AllAllAll
ApplicationArubanetworksAruba InstantAllAllAllAll
ApplicationArubanetworksAruba Instant4.2.3.1AllAllAll
  • cpe:2.3:a:arubanetworks:airwave_network_management:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:arubanetworks:airwave_network_management:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:arubanetworks:aruba_instant:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:arubanetworks:aruba_instant:4.2.3.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:arubanetworks:aruba_instant:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:arubanetworks:aruba_instant:4.2.3.1:*:*:*:*:*:*:*: