A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos S | — | The vulnerabilities contained in this advisory can be addressed by patching or upgrading to one of the AOS-S firmware versions listed below: AOS-S 15.16.xxxx: A.15.16.0024 and above, AOS-S 16.02.xxxx: K.16.02.0035 and above, AOS-S 16.04.xxxx: KA/RA.16.04.0025 and above, AOS-S 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0026 and above, AOS-S 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0021 and above, AOS-S 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0021 and above, AOS-S 16.11.xxxx: KB/WC/YA/YB/YC.16.11.0005 and above. | Mar 6, 2025 | May 3, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub