QID 43857
Date Published: 2021-09-27
QID 43857: Hewlett Packard Enterprise (HPE) ArubaOS Buffer Overflow Vulnerability (ARUBA-PSA-2021-016)
Aruba Networks provides data networking solutions for enterprises and businesses worldwide.
CVE-2021-37716: Buffer Overflow Vulnerabilities in the PAPI protocol.
Affected Versions:
- ArubaOS 8.3.0.x: 8.3.0.14 and below.
- ArubaOS 8.5.0.x: 8.5.0.11 and below.
- ArubaOS 8.6.0.x: 8.6.0.7 and below.
- ArubaOS 8.7.x.x: 8.7.1.1 and below.
QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system
Solution
Please refer to ARUBA-PSA-2021-016 for more information about patching these vulnerabilities.Workaround:
For CVE-2021-37716: Enabling the Enhanced PAPI Security feature where available will prevent exploitation of these vulnerabilities.
For CVE-2021-37716: Enabling the Enhanced PAPI Security feature where available will prevent exploitation of these vulnerabilities.
Vendor References
- ARUBA-PSA-2021-016 -
www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt
CVEs related to QID 43857
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ARUBA-PSA-2021-016 |
|