Vulnerability Description
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be used to perform an authentication bypass and ultimately gain administrative access on the web administrative interface.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Airwave Glass | < 1.3.3 |
Related Weaknesses (CWE)
References
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-001.txtVendor Advisory
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-001.txtVendor Advisory
FAQ
What is CVE-2020-24641?
CVE-2020-24641 is a vulnerability with a CVSS score of 7.5 (HIGH). In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive infor...
How severe is CVE-2020-24641?
CVE-2020-24641 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24641?
Check the references section above for vendor advisories and patch information. Affected products include: Arubanetworks Airwave Glass.