Security Advisory
CVE-2020-24638
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root on the underlying host operating system.