2025年4月9日星期三

Aruba Products Multiple Vulnerabilities

Aruba Products Multiple Vulnerabilities

Release Date: 9 Apr 2025

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

Multiple vulnerabilities were identified in Aruba Products. A remote attacker could exploit this vulnerability to trigger cross-site scripting, sensitive information disclosure, data manipulation and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Data Manipulation
  • Information Disclosure
  • Cross-Site Scripting

System / Technologies affected

HPE Aruba Networking:

 

  • Access Points running AOS-8 Instant
  • Access Points running AOS-10 AP
  • Mobility Conductor
  • Mobility Controllers
  • WLAN and SD-WAN Gateways Managed by HPE Aruba Networking Central

Affected Software Version(s):

 

  • AOS-8.12.x.x: 8.12.0.3 and below
  • AOS-8.10.x.x: 8.10.0.15 and below
  • AOS-8 Instant 8.12.x.x: 8.12.0.3 and below
  • AOS-8 Instant 8.10.x.x: 8.10.0.15 and below
  • AOS-10.7.x.x: 10.7.1.0 and below
  • AOS-10.4.x.x: 10.4.1.6 and below
  • AOS-10 AP 10.7.x.x: 10.7.0.1 and below
  • AOS-10 AP 10.4.x.x: 10.4.1.5 and below

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

思科產品多個漏洞

思科產品多個漏洞 發佈日期: 2025年05月09日 風險: 中度風險 類型: 保安軟件及應用設備 - 保安軟件及應用設備 於思科產品發現多個漏...