PT-2021-7450 · Aruba · Aruba Instant
Published
2021-03-09
·
Updated
2022-05-12
·
CVE-2020-24636
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Aruba Instant versions 6.5.4.17 and below
Aruba Instant versions 8.3.0.13 and below
Aruba Instant versions 8.5.0.10 and below
Aruba Instant versions 8.6.0.5 and below
Aruba Instant versions 8.7.0.0 and below
Description
The issue is related to a lack of data sanitization on the management level, allowing a remote attacker to execute arbitrary commands by sending specially crafted data. This can be exploited to gain unauthorized access and control.
Recommendations
For Aruba Instant versions 6.5.4.17 and below, update to a version above 6.5.4.17 to address the security vulnerability.
For Aruba Instant versions 8.3.0.13 and below, update to a version above 8.3.0.13 to address the security vulnerability.
For Aruba Instant versions 8.5.0.10 and below, update to a version above 8.5.0.10 to address the security vulnerability.
For Aruba Instant versions 8.6.0.5 and below, update to a version above 8.6.0.5 to address the security vulnerability.
For Aruba Instant versions 8.7.0.0 and below, update to a version above 8.7.0.0 to address the security vulnerability.
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aruba Instant