AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-7084

CRITICAL · CVSS 9.8 EPSS 4.63%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-05-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-7084
Severity
CRITICAL
CVSS
9.8
EPSS
4.63%

Original NVD Description

A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.1