QID 43868
Date Published: 2021-09-28
QID 43868: Hewlett Packard Enterprise (HPE) ArubaOS Remote Path Traversal Vulnerability (ARUBA-PSA-2021-016)
Aruba Networks provides data networking solutions for enterprises and businesses worldwide.
CVE-2021-37733: Authenticated Remote Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Read.
Affected Versions:
- ArubaOS 8.3.0.x: 8.3.0.15 and below
- ArubaOS 8.5.0.x: 8.5.0.10 and below
- ArubaOS 8.6.0.x: 8.6.0.6 and below
- ArubaOS 8.7.x.x: 8.7.1.0 and below
QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.
Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
Solution
Please refer to ARUBA-PSA-2021-016 for more information about patching these vulnerabilities.Workaround:
Block access to the ArubaOS Command Line Interface from all untrusted users.
Block access to the ArubaOS Command Line Interface from all untrusted users.
Vendor References
- ARUBA-PSA-2021-016 -
www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt
CVEs related to QID 43868
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ARUBA-PSA-2021-016 |
|