CVE-2021-41001: Command Injection
An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.09.xxxx: 10.09.0002 and below. Aruba has released upgrades for Aruba AOS-CX devices that address this security vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41001?
CVE-2021-41001 is an authenticated remote code execution vulnerability in the AOS-CX Network Analytics Engine (NAE) in Aruba CX switches.
Which products are affected by CVE-2021-41001?
Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series.
What is the severity of CVE-2021-41001?
CVE-2021-41001 has a severity rating of 8.8 (critical).
How can I fix CVE-2021-41001?
To fix CVE-2021-41001, apply the necessary security updates provided by Aruba Networks.
Where can I find more information about CVE-2021-41001?
More information about CVE-2021-41001 can be found in the Aruba Networks security advisory at the following URL: [Link](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-004.txt).