CVE-2020-24639: Arubanetworks Airwave Glass

Critical severity, CVSS 9.8. EPSS: 7.6% chance of exploitation in the next 30 days.

There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete compromise of the underlying host operating system.

Affected products

Published 2021-01-15. Last modified 2026-06-17.