CVE-2016-8526

Public Exploit

Description

Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because the XML parser has access to the local filesystem and runs with the permissions of the web server, it can access any file that is readable by the web server and copy it to an external system of the attacker's choosing. This could include files that contain passwords, which could then lead to privilege escalation.

Category

8.8
CVSS
Severity: High
CVSS 3.0 •
CVSS 2.0 •
EPSS 4.42% Top 15%
Vendor Advisory arubanetworks.com
Affected: Hewlett Packard Enterprise Aruba AirWave
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2016-8526?
CVE-2016-8526 has been scored as a high severity vulnerability.
How to fix CVE-2016-8526?
To fix CVE-2016-8526, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2016-8526 being actively exploited in the wild?
It is possible that CVE-2016-8526 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~4% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2016-8526?
CVE-2016-8526 affects Hewlett Packard Enterprise Aruba AirWave.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.