XML External Entity Vulnerability in Aruba Airwave
CVE-2016-8526
8.8HIGH
Summary
Aruba Airwave prior to version 8.2.3.1 is susceptible to an XML external entity (XXE) attack, allowing an attacker to control XML file contents. This can lead to unauthorized access to sensitive information on the local filesystem of the web server. Exploiting this vulnerability could enable attackers to extract files containing confidential data, such as passwords, potentially resulting in privilege escalation and further compromising system security.
Affected Version(s)
Aruba AirWave all versions up to, but not including, 8.2.3.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved