A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.
CVSS Details
- CVSS 3.1 Base Score: 3.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | — | Upgrade affected HPE Aruba Networking CX 10000 Series switches to one of the following HPE Aruba Networking CX Operating System branches
and versions (as applicable) to resolve the vulnerability described in the
details section:
- AOS-CX 10.15.xxxx: 10.15.1000 and above
- AOS-CX 10.14.xxxx: 10.14.1030 and above
- AOS-CX 10.13.xxxx: 10.13.1070 and above
Note: AOS-CX 10.10.xxxx will not receive fixes for this vulnerability due to
regression complications. Upgrading to AOS-CX 10.13.1070 and above will address
it.
Software versions with resolution/fixes for the vulnerability covered
above, can be downloaded from the HPE Networking Support Portal.
https://networkingsupport.hpe.com/home/
HPE Aruba Networking does not evaluate or patch product versions
that have reached their End of Maintenance (EoM) milestone. For more
information about HPE Aruba Networking product's End of Support policy, visit the
HPE Networking Support Portal at https://networkingsupport.hpe.com/
Following are the supported HPE Aruba Networking CX Operating System software branches for the CX 10000 series switches as of the publication date of this advisory:
- AOS-CX 10.15.xxxx
- AOS-CX 10.14.xxxx
- AOS-CX 10.13.xxxx
- AOS-CX 10.10.xxxx | Feb 24, 2025 | Jan 8, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub