CVE-2021-25155: High severity aruba instant vulnerability
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.x: 8.7.1.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-25155.
What is the severity level of CVE-2021-25155?
The severity level of CVE-2021-25155 is high with a severity value of 6.5.
Which Aruba Instant Access Point products are affected by CVE-2021-25155?
The Aruba Instant Access Point products affected by CVE-2021-25155 are Aruba Instant 6.4.x, Aruba Instant 6.5.x, Aruba Instant 8.3.x, and Aruba Instant 8.5.x.
How can the vulnerability be exploited?
The vulnerability can be exploited remotely to perform arbitrary file modifications.
Are there any patches or updates available to fix CVE-2021-25155?
Yes, patches and updates are available to fix CVE-2021-25155. It is recommended to update to the latest version of the affected software.