Aruba Networks ArubaOS SNMP Community String Information Disclosure Vulnerability
BID:32102
Info
Aruba Networks ArubaOS SNMP Community String Information Disclosure Vulnerability
| Bugtraq ID: | 32102 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-7095 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | nnposter |
| Vulnerable: |
Aruba Networks ArubaOS 3.3.2 6 |
| Not Vulnerable: | |
Discussion
Aruba Networks ArubaOS SNMP Community String Information Disclosure Vulnerability
ArubaOS is the operating system used by various Aruba Networks network devices, including the Aruba Mobility Controller.
ArubaOS is prone to a remote information-disclosure vulnerability related to its implementation of the Simple Network Management Protocol (SNMP).
A remote attacker may exploit this issue to gain information about SNMP community strings. This may aid in further attacks.
ArubaOS 3.3.2.6 is vulnerable; other versions may also be affected.
ArubaOS is the operating system used by various Aruba Networks network devices, including the Aruba Mobility Controller.
ArubaOS is prone to a remote information-disclosure vulnerability related to its implementation of the Simple Network Management Protocol (SNMP).
A remote attacker may exploit this issue to gain information about SNMP community strings. This may aid in further attacks.
ArubaOS 3.3.2.6 is vulnerable; other versions may also be affected.
Exploit / POC
Aruba Networks ArubaOS SNMP Community String Information Disclosure Vulnerability
An attacker may exploit this issue using commonly available networking tools.
An attacker may exploit this issue using commonly available networking tools.
Solution / Fix
Aruba Networks ArubaOS SNMP Community String Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Aruba Networks ArubaOS SNMP Community String Information Disclosure Vulnerability
References:
References: