CVE-2020-7119
Summary
| CVE | CVE-2020-7119 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-04 12:15:00 UTC |
| Updated | 2020-09-09 17:53:00 UTC |
| Description | A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Arubanetworks | Analytics And Location Engine | All | All | All | All |
| Application | Arubanetworks | Analytics And Location Engine | 2.0.0.0 | All | All | All |
| Application | Arubanetworks | Analytics And Location Engine | All | All | All | All |
| Application | Arubanetworks | Analytics And Location Engine | 2.0.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-008.txt | MISC | www.arubanetworks.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.