QID 44175
Date Published: 2024-03-19
QID 44175: Hewlett Packard Enterprise (HPE) ArubaOS Multiple Security Vulnerabilities (ARUBA-PSA-2024-002)
Aruba Networks provides data networking solutions for enterprises and businesses worldwide.
CVE-2024-1356, CVE-2024-25611, CVE-2024-25612, CVE-2024-25613: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.
CVE-2024-25614: There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS.
CVE-2024-25615: An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x.
CVE-2024-25616: Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process.
Affected Software Versions:
ArubaOS 10.5.x.x: 10.5.0.1 and below.
ArubaOS 10.4.x.x: 10.4.0.3 and below.
ArubaOS 8.11.x.x: 8.11.2.0 and below.
ArubaOS 8.10.x.x: 8.10.0.9 and below.
The following ArubaOS and SD-WAN software versions are End of Maintenance are affected by these vulnerabilities and are not patched by this advisory:
ArubaOS 10.3.x.x: all
ArubaOS 8.9.x.x: all
ArubaOS 8.8.x.x: all
ArubaOS 8.7.x.x: all
ArubaOS 8.6.x.x: all
ArubaOS 6.5.4.x: all
QID Detection Logic (Unauthenticated):
This QID gets the vulnerable ArubaOS version via SNMP.
QID Detection Logic(Authenticated):
This will execute the command "show version" and then check the ArubaOS Version.
Successful exploitation of these vulnerabilities may compromise Confidentiality, Integrity, and Availability of the data.
Workaround:
CVE-2024-25615: Enabling the Enhanced PAPI Security feature using a non-default key will prevent exploitation of this vulnerability. Please contact HPE Services - Aruba Networking TAC for any configuration assistance.
CVE-2024-25614: To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above.
CVE-2024-1356, CVE-2024-25611, CVE-2024-25612, CVE-2024-25613: To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Aruba Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above.
- ARUBA-PSA-2024-002 -
www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-002.txt
CVEs related to QID 44175
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ARUBA-PSA-2024-002 |
|