CVE-2021-25157: Medium severity aruba instant vulnerability
A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.x: 8.7.1.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25157.
What is the severity of CVE-2021-25157?
The severity of CVE-2021-25157 is medium.
Which products are affected by CVE-2021-25157?
Aruba Instant Access Point (IAP) products in versions: Aruba Instant 6.4.x, Aruba Instant 6.5.x, Aruba Instant 8.3.x, Aruba Instant 8.5.x, and Siemens Scalance W1750d Firmware.
What is the fix for CVE-2021-25157?
Update affected Aruba Instant Access Point (IAP) products to the recommended versions provided by the vendor.
Are Siemens Scalance W1750d devices vulnerable to CVE-2021-25157?
No, Siemens Scalance W1750d devices are not vulnerable to CVE-2021-25157.