Aruba Update
3291Warning Date
Severity Level
Warning Number
Target Sector
16 September, 2020
● High
2020-1780
All
Description:
Aruba has released a security update to address a vulnerability in the following product:
- AirWave Management Platform
- 8.2.9.1 and below
- Aruba Instant (IAP)
- 6.5.4.16, 8.3.0.12, 8.4.0.6, 8.5.0.6 and below
- Controllers and Gateways
- ArubaOS 6.5.4.16, 8.2.2.8, 8.3.0.12, 8.4.0.6, 8.5.0.9 and below
- x86 Mobility Master 8.7.0.0 and below
- Aruba SD-WAN 8.1.0.0-1.0.4.x, 8.4.0.0-1.0.6.x, 8.5.0.0-1.0.7.x 8.5.0.0-2.0.0.0
- ArubaOS-CX switches
- 10.2.0060 and below
- ClearPass Policy Manager
- 6.7.12, 6.8.3 and below
- CX Switches
- 8400 Series
- 8325 Series
- 8320 Series
- 6400 Series
- 6300 Series
- 6200 Series
Threats:
An attacker could exploit this vulnerability by doing the following:
- Execute arbitrary code.
- Denial of service attack (DoS).
Best practice and Recommendations:
The CERT team encourages users to review Aruba security advisory and apply the necessary update: