PT-2021-7726 · Aruba · Aruba Instant

Published

2021-03-30

·

Updated

2022-06-04

·

CVE-2021-25150

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Aruba Instant versions 6.5.4.17 and below Aruba Instant versions 8.3.0.13 and below Aruba Instant versions 8.5.0.10 and below Aruba Instant versions 8.6.0.4 and below
Description A remote execution of arbitrary commands issue exists due to lack of protection of the command-line interface. Exploitation of this issue may allow a remote attacker to execute arbitrary commands.
Recommendations For Aruba Instant versions 6.5.4.17 and below, apply the released patch to address the security issue. For Aruba Instant versions 8.3.0.13 and below, apply the released patch to address the security issue. For Aruba Instant versions 8.5.0.10 and below, apply the released patch to address the security issue. For Aruba Instant versions 8.6.0.4 and below, apply the released patch to address the security issue.

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01932
CVE-2021-25150

Affected Products

Aruba Instant