Aruba Alert
2806Warning Date
Severity Level
Warning Number
Target Sector
2 June, 2022
● Critical
2022-4907
All
Description:
Aruba has released security updates to address multiple vulnerabilities in the following products:
- AirWave Management Platform
- 8.2.14.0 and below
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.0 and below
- Aruba ClearPass Policy Manager
- 6.10.4 and below
- 6.9.10 and below
- 6.8.9 without Hotfix for Q1 2022 Security issues
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.3 and below
- ECOS 9.0.6.0 and below
- ECOS 8.3.6.0 and below
- Impact of this vulnerability on ECOS is very low.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- See resolution section for details
- ArubaOS-CX Switches
- 10.09.1010 and below
- 10.08.1050 and below
- 10.07.0070 and below
- 10.06.0190 and below
- Aruba NetEdit
- - 2.3.0 and below
Threats:
An attacker could exploit these vulnerabilities by doing the follwoing:
- Denial of service attack (DoS)
Best practice and Recommendations:
The CERT team encourages users to review Aruba security advisory and apply the necessary updates: