QID 43867
Date Published: 2021-09-27
QID 43867: Hewlett Packard Enterprise (HPE) ArubaOS Denial of Service (DoS) Vulnerability (ARUBA-PSA-2021-016)
Aruba Networks provides data networking solutions for enterprises and businesses worldwide.
CVE-2021-37729: Authenticated Remote Path Traversal leading to Denial of Service in ArubaOS Web-based Management User Interface.
Affected Versions:
- ArubaOS 6.4.4.x: 6.4.4.24 and below
- ArubaOS 6.5.4.x: 6.5.4.18 and below
- ArubaOS 8.3.0.x: 8.3.0.15 and below
- ArubaOS 8.5.0.x: 8.5.0.11 and below
- ArubaOS 8.6.0.x: 8.6.0.8 and below
- ArubaOS 8.7.x.x: 8.7.1.2 and below
QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.
Successful exploitation of this vulnerability may affect Integrity and Availability.
Solution
Please refer to ARUBA-PSA-2021-016 for more information about patching these vulnerabilities.Workaround:
Block access to the ArubaOS web-based management interface from all untrusted users.
Block access to the ArubaOS web-based management interface from all untrusted users.
Vendor References
- ARUBA-PSA-2021-016 -
www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt
CVEs related to QID 43867
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ARUBA-PSA-2021-016 |
|