First published: Tue Sep 07 2021(Updated: )
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Sd-wan | >=2.2.0.0<2.2.0.4 | |
Arubanetworks Arubaos | >=8.3.0.0<8.3.0.15 | |
Arubanetworks Arubaos | >=8.5.0.0<8.5.0.12 | |
Arubanetworks Arubaos | >=8.6.0.0<8.6.0.8 | |
Arubanetworks Arubaos | >=8.7.0.0<8.7.1.2 | |
Arubanetworks 7005 | ||
Arubanetworks 7008 | ||
Arubanetworks 7010 | ||
Arubanetworks 7024 | ||
Arubanetworks 7030 | ||
Arubanetworks 7205 | ||
Arubanetworks 7210 | ||
Arubanetworks 7220 | ||
Arubanetworks 7240xm | ||
Arubanetworks 7280 | ||
Arubanetworks 9004 | ||
Arubanetworks 9004-lte | ||
Arubanetworks 9012 | ||
Siemens Scalance W1750d Firmware | <8.7.1.3 | |
Siemens SCALANCE W1750D |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37731 is a local path traversal vulnerability discovered in Aruba SD-WAN Software and Gateways and Aruba Operating System Software versions prior to 8.6.0.0-2.2.0.4, 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16.
CVE-2021-37731 has a severity rating of 6.2 (High).
Aruba SD-WAN Software and Gateways and ArubaOS versions prior to 8.6.0.0-2.2.0.4, 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16 are affected by CVE-2021-37731.
Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address the vulnerability. Please refer to the Aruba advisory for specific patching instructions.
CVE-2021-37731 is associated with CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).