Aruba Updates
2666Warning Date
Severity Level
Warning Number
Target Sector
10 March, 2021
● Critical
2021-2605
All
Description:
Aruba has released security updates to address multiple vulnerabilities in the following products:
- Aruba Instant Access Points running:
- Aruba Instant 8.3.x: 8.3.0.15 and above
- Aruba Instant 8.5.x: 8.5.0.12 and above
- Aruba Instant 8.6.x: 8.6.0.8 and above
- Aruba Instant 8.7.x: 8.7.1.2 and above
- Hardware and Virtual implementations of ArubaOS Mobility Conductor(formerly Mobility Master), Aruba Mobility Controllers, Access-Points when managed by Mobility Controllers running:
- ArubaOS 6.4.x: 6.4.4.25 and above
- ArubaOS 6.5.x: 6.5.4.19 and above
- ArubaOS 8.3.x: 8.3.0.15 and above
- ArubaOS 8.5.x: 8.5.0.12 and above
- ArubaOS 8.6.x: 8.6.0.8 and above
- ArubaOS 8.7.x: 8.7.1.2 and above
- Hardware and Virtual implementations of SD-WAN Gateways running:
- ArubaOS 2.2.0.4 and above
- Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below
- Aruba Instant 6.5.x: 6.5.4.16 and below
- Aruba Instant 8.3.x: 8.3.0.12 and below
- Aruba Instant 8.5.x: 8.5.0.6 and below
- Aruba Instant 8.6.x: 8.6.0.2 and below
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Remote Command Injection
- Buffer overflow
Best practice and Recommendations:
The CERT team encourages users to review Aruba security advisory and apply the necessary updates: