4.9
CVE-2020-7119
- EPSS 0.34%
- Published 04.09.2020 12:15:10
- Last modified 21.11.2024 05:36:39
- Source security-alert@hpe.com
- Teams watchlist Login
- Open Login
A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user.
Data is provided by the National Vulnerability Database (NVD)
Arubanetworks ≫ Analytics And Location Engine Version >= 2.1.0.0 < 2.1.0.3
Arubanetworks ≫ Analytics And Location Engine Version2.0.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.34% | 0.539 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|