Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.09.xxxx: 10.09.0002 and below. Aruba has released upgrades for Aruba AOS-CX devices that address these security vulnerabilities.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | — | The vulnerabilities contained in this advisory can be addressed
by patching or upgrading to one of the versions listed below
AOS-CX 10.06.xxxx: 10.06.0180 and above
AOS-CX 10.07.xxxx: 10.07.0061 and above
AOS-CX 10.08.xxxx: 10.08.1040 and above
AOS-CX 10.09.xxxx: 10.09.0010 and above
Aruba recommends that users using the following branches
upgrade to 10.06.0180 and above to address these vulnerabilities:
AOS-CX 10.05.xxxx and below
None of the above branch versions will address the UEFI
vulnerabilities mentioned in ARUBA-PSA-2022-001. | Feb 24, 2025 | Feb 22, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub