PT-2021-21839 · Aruba · Aruba Operating System

Published

2021-09-07

·

Updated

2022-02-11

·

CVE-2021-37724

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Aruba Operating System Software versions prior to 8.7.1.2 Aruba Operating System Software version 8.6.0.8 Aruba Operating System Software version 8.5.0.12 Aruba Operating System Software version 8.3.0.16
Description: A remote arbitrary command execution issue was discovered in Aruba Operating System Software. This allows for the execution of commands by remote attackers. Aruba has released patches for ArubaOS to address this issue.
Recommendations: For versions prior to 8.7.1.2, update to version 8.7.1.2 or later to resolve the issue. For version 8.6.0.8, update to a version later than 8.6.0.8 to resolve the issue. For version 8.5.0.12, update to a version later than 8.5.0.12 to resolve the issue. For version 8.3.0.16, update to a version later than 8.3.0.16 to resolve the issue.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37724

Affected Products

Aruba Operating System