CVE-2021-37725: CSRF
A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.8.0.1, 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Aruba SD-WAN Software and Gatewaysto a version that resolves this vulnerability.Fixed in 8.6.0.4-2.2.0.4 - Upgrade
Upgrade
Aruba SD-WAN Software and Gatewaysto a version that resolves this vulnerability.Fixed in 8.8.0.1 - Upgrade
Upgrade
Aruba SD-WAN Software and Gatewaysto a version that resolves this vulnerability.Fixed in 8.7.1.2 - Upgrade
Upgrade
Aruba SD-WAN Software and Gatewaysto a version that resolves this vulnerability.Fixed in 8.6.0.8 - Upgrade
Upgrade
Aruba SD-WAN Software and Gatewaysto a version that resolves this vulnerability.Fixed in 8.5.0.12 - Upgrade
Upgrade
Aruba SD-WAN Software and Gatewaysto a version that resolves this vulnerability.Fixed in 8.3.0.15
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2021-37725.
What is the severity of CVE-2021-37725?
The severity of CVE-2021-37725 is high with a severity value of 8.1.
Which software versions are affected by CVE-2021-37725?
CVE-2021-37725 affects Aruba SD-WAN Software and Gateways version(s) prior to 8.6.0.4-2.2.0.4, 8.8.0.1, 8.7.1.2, 8.6.0.8, 8.5.0.12, and 8.3.0.15, as well as Siemens Scalance W1750d Firmware version up to 8.7.1.3.
What is the vulnerability type of CVE-2021-37725?
CVE-2021-37725 is a remote cross-site request forgery (CSRF) vulnerability.
Are there any patches or fixes available for CVE-2021-37725?
Aruba has released patches for Aruba SD-WAN Software and Gateways to address the vulnerability. Please refer to the official Aruba advisory for more information.