QID 43856

Date Published: 2021-10-05

QID 43856: Hewlett Packard Enterprise (HPE) ArubaOS SAD Domain Name System (DNS) Side Channel Vulnerability (ARUBA-PSA-2021-008)

Aruba Networks provides data networking solutions for enterprises and businesses worldwide.

CVE-2020-25705: A vulnerability made public under the name SAD DNS affects Domain Name System resolvers due to a vulnerability in the Linux kernel when handling ICMP packets. This vulnerability is present in some Aruba products which are listed below.
Affected Versions:
-- ArubaOS 6.4.x prior to 6.4.4.25
-- ArubaOS 6.5.x: prior to 6.5.4.19
-- ArubaOS 8.3.x: prior to 8.3.0.15
-- ArubaOS 8.5.x: prior to 8.5.0.12
-- ArubaOS 8.6.x: prior to 8.6.0.8
-- ArubaOS 8.7.x: prior to 8.7.1.2
-- ArubaOS prior to 2.2.0.4

QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.

A flaw in the way reply ICMP packets are limited in the Linux kernel was found that allows for quick scanning of open UDP ports. This flaw allows an off-path remote user to effectively bypass source port UDP randomization.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Please refer to ARUBA-PSA-2021-008 for more information about patching these vulnerabilities.
    Vendor References

    CVEs related to QID 43856

    Software Advisories
    Advisory ID Software Component Link
    ARUBA-PSA-2021-008 URL Logo www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-008.txt