QID 43828

Date Published: 2021-06-01

QID 43828: HPE ArubaOS Multiple Vulnerabilities (ARUBA-PSA-2021-011)

Aruba Networks provides data networking solutions for enterprises and businesses worldwide.

CVE-2020-26146: The Aruba Access Point does not check whether all fragments of a frame have consecutive PN, that is, whether the fragments indeed belong to the same frame or not.
CVE-2020-24588: Due to some misconfiguration an attacker can alter A-MSDU bit from the QoS Control subfield of the 802.11 MAC header and steal sensitive data.

Affected Versions:
-- ArubaOS 6.4.x prior to 6.4.4.25
-- ArubaOS 6.5.x: prior to 6.5.4.19
-- ArubaOS 8.3.x: prior to 8.3.0.15
-- ArubaOS 8.5.x: prior to 8.5.0.12
-- ArubaOS 8.6.x: prior to 8.6.0.8
-- ArubaOS 8.7.x: prior to 8.7.1.2

QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.

Successful exploitation of these vulnerabilities may allow an attacker to steal or inject victim data using MitM attack.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.8 severity.
  • Solution
    Please refer to ARUBA-PSA-2021-011 for more information about patching these vulnerabilities.
    Vendor References

    CVEs related to QID 43828

    Software Advisories
    Advisory ID Software Component Link
    ARUBA-PSA-2021-011 URL Logo www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-011.txt