First published: Tue Feb 09 2021(Updated: )
A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Aruba 5406r Zl2 Firmware | <kb.16.10.0012 | |
Arubanetworks Aruba 5406r Zl2 | ||
Arubanetworks Aruba 5412r Zl2 Firmware | <kb.16.10.0012 | |
Arubanetworks Aruba 5412r Zl2 | ||
Arubanetworks Aruba 3810m Firmware | <kb.16.10.0012 | |
Arubanetworks Aruba 3810m | ||
Arubanetworks Aruba 2930m Firmware | <wc.16.10.0012 | |
Arubanetworks Aruba 2930m | ||
Arubanetworks Aruba 2930f Firmware | <wc.16.10.0012 | |
Arubanetworks Aruba 2930f | ||
Arubanetworks Aruba 2920 Firmware | <wb.16.10.0011 | |
Arubanetworks Aruba 2920 | ||
Arubanetworks Aruba 2540 Firmware | <yc.16.10.0012 | |
Arubanetworks Aruba 2540 | ||
Arubanetworks Aruba 2530ya Firmware | <ya.16.10.0012 | |
Arubanetworks Aruba 2530ya | ||
Arubanetworks Aruba 3800 Firmware | <ka.16.04.0022 | |
Arubanetworks Aruba 3800 | ||
Arubanetworks Aruba 2620 Firmware | <ra.16.04.0022 | |
Arubanetworks Aruba 2620 | ||
Hpe 8200 Zl Firmware | <k.15.18.0024 | |
Hpe 8200 Zl | ||
Hpe 6200 Yl Firmware | <k.15.18.0024 | |
Hpe 6200 Yl | ||
Hpe 3500 Firmware | <k.16.02.0032 | |
Hpe 3500 | ||
Hpe 3500 Yl Firmware | <k.16.02.0032 | |
Hpe 3500 Yl | ||
Arubanetworks Aruba 2530yb Firmware | <yb.16.10.0012 | |
Arubanetworks Aruba 2530yb |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25141 is a security vulnerability in certain HPE and Aruba L2/L3 switch firmware.
CVE-2021-25141 could be exploited to cause a denial-of-service condition on the switch's management interface.
CVE-2021-25141 has a severity rating of 4.4 out of 10 (medium severity).
The affected software versions include Arubanetworks Aruba 5406r Zl2 Firmware (up to exclusive version kb.16.10.0012), Arubanetworks Aruba 5412r Zl2 Firmware (up to exclusive version kb.16.10.0012), Arubanetworks Aruba 3810m Firmware (up to exclusive version kb.16.10.0012), Arubanetworks Aruba 2930m Firmware (up to exclusive version wc.16.10.0012), Arubanetworks Aruba 2930f Firmware (up to exclusive version wc.16.10.0012), Arubanetworks Aruba 2920 Firmware (up to exclusive version wb.16.10.0011), Arubanetworks Aruba 2540 Firmware (up to exclusive version yc.16.10.0012), Arubanetworks Aruba 2530ya Firmware (up to exclusive version ya.16.10.0012), Arubanetworks Aruba 3800 Firmware (up to exclusive version ka.16.04.0022), and Arubanetworks Aruba 2620 Firmware (up to exclusive version ra.16.04.0022).
To fix CVE-2021-25141, it is recommended to upgrade to a fixed firmware version provided by HPE or Aruba Networks.