PT-2022-11349 · Aruba · Aruba 8325 Switch Series+7
Published
2022-03-02
·
Updated
2022-09-27
·
CVE-2021-41000
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Aruba CX 6200F Switch Series versions 10.06.xxxx through 10.06.0170 and below
Aruba 6300 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below
Aruba 6400 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below
Aruba 8320 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below
Aruba 8325 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below
Aruba 8400 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below
Aruba CX 8360 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below
Description
Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface. Aruba has released upgrades for Aruba AOS-CX devices that address these security vulnerabilities.
Recommendations
For Aruba CX 6200F Switch Series version 10.06.xxxx, update to a version above 10.06.0170.
For Aruba 6300 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050.
For Aruba 6300 Switch Series version 10.08.xxxx, update to a version above 10.08.1030.
For Aruba 6400 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050.
For Aruba 6400 Switch Series version 10.08.xxxx, update to a version above 10.08.1030.
For Aruba 8320 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050.
For Aruba 8320 Switch Series version 10.08.xxxx, update to a version above 10.08.1030.
For Aruba 8325 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050.
For Aruba 8325 Switch Series version 10.08.xxxx, update to a version above 10.08.1030.
For Aruba 8400 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050.
For Aruba 8400 Switch Series version 10.08.xxxx, update to a version above 10.08.1030.
For Aruba CX 8360 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050.
For Aruba CX 8360 Switch Series version 10.08.xxxx, update to a version above 10.08.1030.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aos-Cx
Aruba 6300 Switch Series
Aruba 6400 Switch Series
Aruba 8320 Switch Series
Aruba 8325 Switch Series
Aruba 8400 Switch Series
Aruba Cx 6200F Switch Series
Aruba Cx 8360 Switch Series