QID 43860
Date Published: 2021-09-27
QID 43860: Hewlett Packard Enterprise (HPE) ArubaOS Remote Command Execution Vulnerability (ARUBA-PSA-2021-016)
Aruba Networks provides data networking solutions for enterprises and businesses worldwide.
CVE-2021-37717, CVE-2021-37718: Authenticated Remote Command Execution in ArubaOS Web-based Management User Interface
Affected Versions:
- ArubaOS 8.3.0.x: 8.3.0.15 and below
- ArubaOS 8.5.0.x: 8.5.0.11 and below
- ArubaOS 8.6.0.x: 8.6.0.6 and below
- ArubaOS 8.7.x.x: 8.7.1.3 and below
QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.
Successful exploitation of this vulnerability may allow an authenticated attacker to execute arbitrary code on the target system
Solution
Please refer to ARUBA-PSA-2021-016 for more information about patching these vulnerabilities.Workaround:
Block access to the ArubaOS web-based management interface from all untrusted users.
Block access to the ArubaOS web-based management interface from all untrusted users.
Vendor References
- ARUBA-PSA-2021-016 -
www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt
CVEs related to QID 43860
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ARUBA-PSA-2021-016 |
|