Remote Code Execution Vulnerabilities in Aruba Networks Switch Products
CVE-2021-41000

8.8HIGH

Summary

Multiple remote code execution vulnerabilities were identified in the AOS-CX command line interface, affecting various models of Aruba's switch series. These vulnerabilities allow authenticated attackers to execute arbitrary code, posing a significant risk to the integrity and security of the network. Affected products include the Aruba CX 6200F, 6300, 6400, 8320, 8325, 8400, and CX 8360 Switch Series, with specified vulnerable firmware versions. Aruba Networks has issued security upgrades to mitigate these vulnerabilities.

Affected Version(s)

Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.