QID 43863
Date Published: 2021-09-27
QID 43863: Hewlett Packard Enterprise (HPE) ArubaOS Cross-Site Request Forgery (CSRF) Vulnerability (ARUBA-PSA-2021-016)
Aruba Networks provides data networking solutions for enterprises and businesses worldwide.
CVE-2021-37725: ArubaOS Cross-Site Request Forgery in ArubaOS Web-based Management User Interface Resulting in File Removal.
Affected Versions:
- ArubaOS 8.3.0.x: 8.3.0.14 and below
- ArubaOS 8.5.0.x: 8.5.0.11 and below
- ArubaOS 8.6.0.x: 8.6.0.7 and below
- ArubaOS 8.7.x.x: 8.7.1.1 and below
- ArubaOS 8.8.0.x: 8.8.0.0
QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.
Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to persuading an authorized user to follow a malicious link, resulting in the deletion of arbitrary files with the privilege level of the targeted user.
- ARUBA-PSA-2021-016 -
www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt
CVEs related to QID 43863
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ARUBA-PSA-2021-016 |
|