Aruba Alert
2909Warning Date
Severity Level
Warning Number
Target Sector
1 March, 2023
● Critical
2023-5480
All
Aruba has released security updates to address several vulnerabilities in the following products:
- Aruba Mobility Conductor (formerly Mobility Master)
- Aruba Mobility Controllers
- WLAN Gateways and SD-WAN Gateways managed by Aruba Central
- ArubaOS
- 8.6.0.19 and below
- 8.10.0.4 and below
- 10.3.1.0 and below
- SD-WAN
- 8.7.0.0-2.3.0.8 and below
Attacker could exploit these vulnerabilities and achieve the following:
- Command Injections
- Stack Buffer Overflow
- Sensitive Information Disclosure
- Remote Command Execution
The CERT team encourages users to review Aruba security advisory and apply the necessary updates:
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-002.txt