Affected Software Versions:
- AOS-10.4.x.x: 10.4.1.4 and below
- Instant AOS-8.12.x.x: 8.12.0.2 and below
- Instant AOS-8.10.x.x: 8.10.0.13 and below
End of Maintenance (EoM) software versions
- AOS-10.6.x.x: all
- AOS-10.5.x.x: all
- AOS-10.3.x.x: all
- Instant AOS-8.11.x.x: all
- Instant AOS-8.9.x.x: all
- Instant AOS-8.8.x.x: all
- Instant AOS-8.7.x.x: all
- Instant AOS-8.6.x.x: all
- Instant AOS-8.5.x.x: all
- Instant AOS-8.4.x.x: all
- Instant AOS-6.5.x.x: all
- Instant AOS-6.4.x.x: all
Multiple vulnerabilities have been reported in Aruba products, which could be exploited by a remote attacker to execute arbitrary code or access sensitive information on the targeted system.
Target Audience
All end-user organizations and individuals of HPE Aruba Networking Products
Risk Assessment
High risk of unauthorized data access and potential system takeovers.
Impact Assessment
Potential for Unauthorized Information Disclosure or Arbitrary Command Execution.
The information provided herein is on "as is" basis, without warranty of any kind.