Aruba Alert
2949Warning Date
Severity Level
Warning Number
Target Sector
17 July, 2022
● Critical
2022-5033
All
Aruba has released a security update to address several vulnerabilities in the following products:
- AirWave Management Platform
- 8.2.14.0 and below
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.0 and below
- Aruba ClearPass Policy Manager
- 6.10.4 and below
- 6.9.10 and below
- 6.8.9 without Hotfix for Q1 2022 Security issues
- ArubaOS-CX Switches
- 10.09.1030 and below
- 10.08.1060 and below
- 10.07.0070 and below
- 10.06.0200 and below
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.3 and below
- ECOS 9.0.6.0 and below
- ECOS 8.3.6.0 and below
- Impact of this vulnerability on ECOS is very low.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
Attacker could exploit these vulnerabilities by doing the following:
- Improper validation of input/output
- Integer overflow
The CERT team encourages users to review Aruba security advisory and apply the necessary updates: