QID 43861
Date Published: 2021-09-27
QID 43861: Hewlett Packard Enterprise (HPE) ArubaOS Remote Command Execution Vulnerability (ARUBA-PSA-2021-016)
Aruba Networks provides data networking solutions for enterprises and businesses worldwide.
CVE-2021-37719, CVE-2021-37720, CVE-2021-37721, CVE-2021-37722: Authenticated Remote Command Execution in ArubaOS Command Line Interface.
Affected Versions:
- ArubaOS 6.4.4.x: 6.4.4.24 and below
- ArubaOS 6.5.4.x: 6.5.4.19 and below
- ArubaOS 8.3.0.x: 8.3.0.15 and below
- ArubaOS 8.5.0.x: 8.5.0.12 and below
- ArubaOS 8.6.0.x: 8.6.0.8 and below
- ArubaOS 8.7.x.x: 8.7.1.3 and below
QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.
Successful exploitation of this vulnerability may allow an authenticated attacker to execute arbitrary code on the target system
Solution
Please refer to ARUBA-PSA-2021-016 for more information about patching these vulnerabilities.Workaround:
Block access to the ArubaOS Command Line Interface from all untrusted users.
Block access to the ArubaOS Command Line Interface from all untrusted users.
Vendor References
- ARUBA-PSA-2021-016 -
www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt
CVEs related to QID 43861
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ARUBA-PSA-2021-016 |
|