Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-001.txt | vendor advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-549547.pdf | third party advisory |
http://www.securityfocus.com/bid/108374 | third party advisory vdb entry |
https://www.us-cert.gov/ics/advisories/ICSA-19-134-07 | mitigation third party advisory us government resource |
https://www.anquanke.com/vul/id/1652568 | third party advisory |