CVE-2021-37731
Published on: 09/07/2021 12:00:00 AM UTC
Last Modified on: 11/26/2021 09:37:00 PM UTC
Certain versions of 7005 from Arubanetworks contain the following vulnerability:
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
- CVE-2021-37731 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.2 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
PHYSICAL | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.2 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
www.arubanetworks.com text/plain |
![]() | |
cert-portal.siemens.com application/pdf |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Arubanetworks | 7005 | - | All | All | All |
Hardware
| Arubanetworks | 7008 | - | All | All | All |
Hardware
| Arubanetworks | 7010 | - | All | All | All |
Hardware
| Arubanetworks | 7024 | - | All | All | All |
Hardware
| Arubanetworks | 7030 | - | All | All | All |
Hardware
| Arubanetworks | 7205 | - | All | All | All |
Hardware
| Arubanetworks | 7210 | - | All | All | All |
Hardware
| Arubanetworks | 7220 | - | All | All | All |
Hardware
| Arubanetworks | 7240xm | - | All | All | All |
Hardware
| Arubanetworks | 7280 | - | All | All | All |
Hardware
| Arubanetworks | 9004 | - | All | All | All |
Hardware
| Arubanetworks | 9004-lte | - | All | All | All |
Hardware
| Arubanetworks | 9012 | - | All | All | All |
Operating System | Arubanetworks | Arubaos | All | All | All | All |
Application | Arubanetworks | Sd-wan | All | All | All | All |
Operating System | Arubanetworks | Sd-wan | All | All | All | All |
Hardware
| Siemens | Scalance W1750d | - | All | All | All |
Operating System | Siemens | Scalance W1750d Firmware | All | All | All | All |
- cpe:2.3:h:arubanetworks:7005:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7008:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7010:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7024:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7030:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7205:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7210:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7220:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7240xm:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7280:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:9004:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:9004-lte:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:9012:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*:
- cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:sd-wan:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_w1750d:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_w1750d_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-37731 : A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba O… twitter.com/i/web/status/1… | 2021-09-07 13:12:58 |