Aruba Products Multiple Vulnerabilities
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities were identified in Aruba Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure, cross-site scripting and security restriction bypass on the targeted system.
Impact
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
- Cross-Site Scripting
System / Technologies affected
- Aruba Mobility Conductor (formerly Mobility Master)
- Aruba Mobility Controllers
- WLAN Gateways and SD-WAN Gateways managed by Aruba Central
Affected Software Versions
- ArubaOS 8.6.0.19 and below
- ArubaOS 8.10.0.4 and below
- ArubaOS 10.3.1.0 and below
- SD-WAN 8.7.0.0-2.3.0.8 and below
The following ArubaOS and SD-WAN software versions that are End of Life are affected by these vulnerabilities and are not patched by this advisory
- ArubaOS 6.5.4.x
- ArubaOS 8.7.x.x
- ArubaOS 8.8.x.x
- ArubaOS 8.9.x.x
- SD-WAN 8.6.0.4-2.2.x.x
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2021-3712
- CVE-2023-22747
- CVE-2023-22748
- CVE-2023-22749
- CVE-2023-22750
- CVE-2023-22751
- CVE-2023-22752
- CVE-2023-22753
- CVE-2023-22754
- CVE-2023-22755
- CVE-2023-22756
- CVE-2023-22757
- CVE-2023-22758
- CVE-2023-22759
- CVE-2023-22760
- CVE-2023-22761
- CVE-2023-22762
- CVE-2023-22763
- CVE-2023-22764
- CVE-2023-22765
- CVE-2023-22766
- CVE-2023-22767
- CVE-2023-22768
- CVE-2023-22769
- CVE-2023-22770
- CVE-2023-22771
- CVE-2023-22772
- CVE-2023-22773
- CVE-2023-22774
- CVE-2023-22775
- CVE-2023-22776
- CVE-2023-22777
- CVE-2023-22778
Source
Related Link
Related Tags
Share with