QID 43986

Date Published: 2023-03-16

QID 43986: Hewlett Packard Enterprise (HPE) ArubaOS Multiple Vulnerabilities (ARUBA-PSA-2022-016)

Aruba Networks provides data networking solutions for enterprises and businesses worldwide.

Aruba has released patches for ArubaOS that address multiple security vulnerabilities.
Affected Versions: - ArubaOS 6.5.4.x : ArubaOS 6.5.4.22 and below
- ArubaOS 8.6.x.x : ArubaOS 8.6.0.17 and below
- ArubaOS 8.7.x.x : ArubaOS 8.7.1.9 and below
- ArubaOS 10.3.x.x : 10.3.0.0
- ArubaOS 8.4.x.x : all
- ArubaOS 8.5.x.x : all
- ArubaOS 8.8.x.x : all
- ArubaOS 8.9.x.x : all

QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.

Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Please refer to ARUBA-PSA-2021-016 for more information about patching these vulnerabilities.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ARUBA-PSA-2022-016 URL Logo www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt