QID 43856
Date Published: 2021-10-05
QID 43856: Hewlett Packard Enterprise (HPE) ArubaOS SAD Domain Name System (DNS) Side Channel Vulnerability (ARUBA-PSA-2021-008)
Aruba Networks provides data networking solutions for enterprises and businesses worldwide.
CVE-2020-25705: A vulnerability made public under the name SAD DNS affects Domain Name System resolvers due to a vulnerability in the Linux kernel when
handling ICMP packets. This vulnerability is present in some Aruba products which are listed below.
Affected Versions:
-- ArubaOS 6.4.x prior to 6.4.4.25
-- ArubaOS 6.5.x: prior to 6.5.4.19
-- ArubaOS 8.3.x: prior to 8.3.0.15
-- ArubaOS 8.5.x: prior to 8.5.0.12
-- ArubaOS 8.6.x: prior to 8.6.0.8
-- ArubaOS 8.7.x: prior to 8.7.1.2
-- ArubaOS prior to 2.2.0.4
QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.
A flaw in the way reply ICMP packets are limited in the Linux kernel was found that allows for quick scanning of open UDP ports. This flaw allows an off-path remote user to effectively bypass source port UDP randomization.
- ARUBA-PSA-2021-008 -
www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-008.txt
CVEs related to QID 43856
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ARUBA-PSA-2021-008 |
|