QID 43988

Date Published: 2023-03-03

QID 43988: Hewlett Packard Enterprise (HPE) ArubaOS Multiple Vulnerabilities (ARUBA-PSA-2023-002)

Aruba Networks provides data networking solutions for enterprises and businesses worldwide.

Aruba has released patches for ArubaOS that address multiple security vulnerabilities.
Affected Versions: ArubaOS 8.6.x.x : 8.6.0.19 and below
ArubaOS 8.10.x.x: 8.10.0.4 and below
ArubaOS 10.3.x.x : 10.3.1.0 and below
The following ArubaOS software versions that are End of Life are affected by these vulnerabilities and are not patched by this advisory:
ArubaOS 6.5.4.x: all
ArubaOS 8.7.x.x : all
ArubaOS 8.8.x.x : all
ArubaOS 8.9.x.x : all

QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.

Note: QID is Potential as per Workaround: To minimize the likelihood of an attacker exploiting these vulnerabilities, Aruba recommends that the communication between Controller/Gateways and Access-Points be restricted either by having a dedicated layer 2 segment/VLAN or, if Controller/Gateways and Access-Points cross layer 3 boundaries, to have firewall policies restricting the communication of these authorized devices. Enabling the Enhanced PAPI Security feature will prevent the PAPI-specific vulnerabilities above from being exploited

Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Please refer to ARUBA-PSA-2023-002 for more information about patching these vulnerabilities.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ARUBA-PSA-2023-002 URL Logo www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-002.txt