CVE-2021-25146: OS Command Injection
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.5 and below; Aruba Instant 8.7.x: 8.7.0.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-25146.
What is the severity of CVE-2021-25146?
The severity of CVE-2021-25146 is critical with a severity value of 7.2.
Which software versions are affected by CVE-2021-25146?
Aruba Instant 6.5.x: up to 6.5.4.17, Aruba Instant 8.3.x: up to 8.3.0.13, Aruba Instant 8.5.x: up to 8.5.0.10, Aruba Instant 8.6.x: up to 8.6.0.5.
How can I fix the vulnerability in Aruba Instant Access Point (IAP) products?
Upgrade your Aruba Instant Access Point (IAP) products to the latest version available.
Where can I find more information about CVE-2021-25146?
You can find more information about CVE-2021-25146 in the following references: [CERT-Portal Siemens](https://cert-portal.siemens.com/productcert/pdf/ssa-723417.pdf), [Aruba Networks PSA-2021-007](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-007.txt).