QID 44071

Date Published: 2023-07-05

QID 44071: Hewlett Packard Enterprise (HPE) ArubaOS Multiple Security Vulnerabilities (ARUBA-PSA-2023-006)

Aruba Networks provides data networking solutions for enterprises and businesses worldwide.

Aruba has released patches for ArubaOS that address multiple security vulnerabilities.
Affected Versions:
ArubaOS 10.3.x.x : 10.3.1.0 and below

NOTE:
Only Aruba Access Points running ArubaOS are affected.

QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please refer to ARUBA-PSA-2023-006 for more information about patching these vulnerabilities.Workaround:
    To minimize the likelihood of an attacker exploiting these vulnerabilities, Aruba recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ARUBA-PSA-2023-006 URL Logo www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-006.txt