PT-2022-11349 · Aruba · Aruba 8325 Switch Series+7

Published

2022-03-02

·

Updated

2022-09-27

·

CVE-2021-41000

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Aruba CX 6200F Switch Series versions 10.06.xxxx through 10.06.0170 and below Aruba 6300 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below Aruba 6400 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below Aruba 8320 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below Aruba 8325 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below Aruba 8400 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below Aruba CX 8360 Switch Series versions 10.06.xxxx through 10.06.0170 and below, 10.07.xxxx through 10.07.0050 and below, 10.08.xxxx through 10.08.1030 and below
Description Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface. Aruba has released upgrades for Aruba AOS-CX devices that address these security vulnerabilities.
Recommendations For Aruba CX 6200F Switch Series version 10.06.xxxx, update to a version above 10.06.0170. For Aruba 6300 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050. For Aruba 6300 Switch Series version 10.08.xxxx, update to a version above 10.08.1030. For Aruba 6400 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050. For Aruba 6400 Switch Series version 10.08.xxxx, update to a version above 10.08.1030. For Aruba 8320 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050. For Aruba 8320 Switch Series version 10.08.xxxx, update to a version above 10.08.1030. For Aruba 8325 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050. For Aruba 8325 Switch Series version 10.08.xxxx, update to a version above 10.08.1030. For Aruba 8400 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050. For Aruba 8400 Switch Series version 10.08.xxxx, update to a version above 10.08.1030. For Aruba CX 8360 Switch Series versions 10.06.xxxx and 10.07.xxxx, update to a version above 10.07.0050. For Aruba CX 8360 Switch Series version 10.08.xxxx, update to a version above 10.08.1030.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-41000

Affected Products

Aos-Cx
Aruba 6300 Switch Series
Aruba 6400 Switch Series
Aruba 8320 Switch Series
Aruba 8325 Switch Series
Aruba 8400 Switch Series
Aruba Cx 6200F Switch Series
Aruba Cx 8360 Switch Series