vulnerability
Aruba AOS-10: CVE-2023-45618: Unauthenticated Arbitrary File Deletion in AirWave Client Service Accessed by the PAPI Protocol
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:P/A:C) | Nov 14, 2023 | Jan 14, 2025 | Feb 4, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:C)
Published
Nov 14, 2023
Added
Jan 14, 2025
Modified
Feb 4, 2025
Description
There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Solution
aruba-aos-10-cve-2023-45618
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.