PT-2021-21845 · Aruba · Aruba Operating System+1
Published
2021-09-07
·
Updated
2021-11-26
·
CVE-2021-37731
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Aruba SD-WAN Software and Gateways versions prior to 8.6.0.0-2.2.0.4
Aruba Operating System Software versions prior to 8.7.1.1
Aruba Operating System Software versions prior to 8.6.0.7
Aruba Operating System Software versions prior to 8.5.0.12
Aruba Operating System Software versions prior to 8.3.0.16
Description:
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways and Aruba Operating System Software. This issue allows for a local path traversal attack. Aruba has released patches that address this security issue.
Recommendations:
For Aruba SD-WAN Software and Gateways version prior to 8.6.0.0-2.2.0.4, apply the released patch to fix the vulnerability.
For Aruba Operating System Software version prior to 8.7.1.1, apply the released patch to fix the vulnerability.
For Aruba Operating System Software version prior to 8.6.0.7, apply the released patch to fix the vulnerability.
For Aruba Operating System Software version prior to 8.5.0.12, apply the released patch to fix the vulnerability.
For Aruba Operating System Software version prior to 8.3.0.16, apply the released patch to fix the vulnerability.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aruba Operating System
Aruba Sd-Wan Software/Gateways