PT-2021-7450 · Aruba · Aruba Instant

Published

2021-03-09

·

Updated

2022-05-12

·

CVE-2020-24636

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Aruba Instant versions 6.5.4.17 and below Aruba Instant versions 8.3.0.13 and below Aruba Instant versions 8.5.0.10 and below Aruba Instant versions 8.6.0.5 and below Aruba Instant versions 8.7.0.0 and below
Description The issue is related to a lack of data sanitization on the management level, allowing a remote attacker to execute arbitrary commands by sending specially crafted data. This can be exploited to gain unauthorized access and control.
Recommendations For Aruba Instant versions 6.5.4.17 and below, update to a version above 6.5.4.17 to address the security vulnerability. For Aruba Instant versions 8.3.0.13 and below, update to a version above 8.3.0.13 to address the security vulnerability. For Aruba Instant versions 8.5.0.10 and below, update to a version above 8.5.0.10 to address the security vulnerability. For Aruba Instant versions 8.6.0.5 and below, update to a version above 8.6.0.5 to address the security vulnerability. For Aruba Instant versions 8.7.0.0 and below, update to a version above 8.7.0.0 to address the security vulnerability.

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06348
CVE-2020-24636

Affected Products

Aruba Instant