Airwave
Vendor:
First CVE: Aug 6, 2018 · Active for 7 years
6
Total CVEs
More Total CVEs than 80% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Airwave over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2018
7 years ago
Most Recent CVE
Sep 5, 2023
1,053 days ago
CVE Severity & Scoring
Airwave6 CVEs
33%
67%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low1 (16.7%)
High2 (33.3%)
None3 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-8527MEDIUM Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirW | Aug 6, 2018 | 6.1 | 47 | NO | YES |
CVE-2016-8526HIGH Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on e | Aug 6, 2018 | 8.8 | 36 | NO | YES |
CVE-2015-1391HIGH Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism. | Sep 5, 2023 | 8.8 | 24 | NO | NO |
CVE-2015-2202HIGH Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS. | Sep 5, 2023 | 7.2 | 21 | NO | NO |
CVE-2015-2201HIGH Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users. | Sep 5, 2023 | 7.2 | 21 | NO | NO |
CVE-2015-1390MEDIUM Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator. | Sep 5, 2023 | 6.1 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
16.7% of CVEs· 98th percentile
ExploitDB
2 CVEs
33.3% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Airwave
Top CWEs
Versions
No cataloged versions.