CVE-2015-1388: OS Command Injection
The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1388?
CVE-2015-1388 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2015-1388?
To fix CVE-2015-1388, upgrade ArubaOS to version 6.3.1.15 or later, or 6.4.2.4 or later.
Which versions of ArubaOS are affected by CVE-2015-1388?
CVE-2015-1388 affects ArubaOS versions 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4.
What can attackers do by exploiting CVE-2015-1388?
By exploiting CVE-2015-1388, attackers can execute arbitrary commands on affected Aruba access points.
Is there a workaround for CVE-2015-1388?
As of now, the recommended action is to update to a safe version, as there are no known effective workarounds for CVE-2015-1388.