Lucene search

K
cveHpeCVE-2021-29148
HistoryJul 22, 2021 - 2:15 p.m.

CVE-2021-29148

2021-07-2214:15:07
CWE-79
hpe
web.nvd.nist.gov
26
3
cve
aruba
cx
switch
xss
vulnerability
security
upgrade
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

33.8%

A local cross-site scripting (XSS) vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): Aruba AOS-CX firmware: 10.04.xxxx - versions prior to 10.04.3070, 10.05.xxxx - versions prior to 10.05.0070, 10.06.xxxx - versions prior to 10.06.0110, 10.07.xxxx - versions prior to 10.07.0001. Aruba has released upgrades for Aruba AOS-CX devices that address this security vulnerability.

Affected configurations

Nvd
Node
arubanetworksaos-cx_firmwareRange10.04.00010.04.3070
OR
arubanetworksaos-cx_firmwareRange10.05.000010.05.0070
OR
arubanetworksaos-cx_firmwareRange10.06.000010.06.0110
OR
arubanetworksaos-cx_firmwareRange10.07.000010.07.0001
AND
arubanetworkscx_6200fMatch-
Node
arubanetworksaos-cx_firmwareRange10.04.00010.04.3070
OR
arubanetworksaos-cx_firmwareRange10.05.000010.05.0070
OR
arubanetworksaos-cx_firmwareRange10.06.000010.06.0110
OR
arubanetworksaos-cx_firmwareRange10.07.000010.07.0001
AND
arubanetworkscx_6300Match-
Node
arubanetworksaos-cx_firmwareRange10.04.00010.04.3070
OR
arubanetworksaos-cx_firmwareRange10.05.000010.05.0070
OR
arubanetworksaos-cx_firmwareRange10.06.000010.06.0110
OR
arubanetworksaos-cx_firmwareRange10.07.000010.07.0001
AND
arubanetworkscx_6400Match-
Node
arubanetworksaos-cx_firmwareRange10.04.00010.04.3070
OR
arubanetworksaos-cx_firmwareRange10.05.000010.05.0070
OR
arubanetworksaos-cx_firmwareRange10.06.000010.06.0110
OR
arubanetworksaos-cx_firmwareRange10.07.000010.07.0001
AND
arubanetworkscx_8320Match-
Node
arubanetworksaos-cx_firmwareRange10.04.00010.04.3070
OR
arubanetworksaos-cx_firmwareRange10.05.000010.05.0070
OR
arubanetworksaos-cx_firmwareRange10.06.000010.06.0110
OR
arubanetworksaos-cx_firmwareRange10.07.000010.07.0001
AND
arubanetworkscx_8325Match-
Node
arubanetworksaos-cx_firmwareRange10.04.00010.04.3070
OR
arubanetworksaos-cx_firmwareRange10.05.000010.05.0070
OR
arubanetworksaos-cx_firmwareRange10.06.000010.06.0110
OR
arubanetworksaos-cx_firmwareRange10.07.000010.07.0001
AND
arubanetworkscx_8360Match-
Node
arubanetworksaos-cx_firmwareRange10.04.00010.04.3070
OR
arubanetworksaos-cx_firmwareRange10.05.000010.05.0070
OR
arubanetworksaos-cx_firmwareRange10.06.000010.06.0110
OR
arubanetworksaos-cx_firmwareRange10.07.000010.07.0001
AND
arubanetworkscx_8400Match-
VendorProductVersionCPE
arubanetworksaos-cx_firmware*cpe:2.3:o:arubanetworks:aos-cx_firmware:*:*:*:*:*:*:*:*
arubanetworkscx_6200f-cpe:2.3:h:arubanetworks:cx_6200f:-:*:*:*:*:*:*:*
arubanetworkscx_6300-cpe:2.3:h:arubanetworks:cx_6300:-:*:*:*:*:*:*:*
arubanetworkscx_6400-cpe:2.3:h:arubanetworks:cx_6400:-:*:*:*:*:*:*:*
arubanetworkscx_8320-cpe:2.3:h:arubanetworks:cx_8320:-:*:*:*:*:*:*:*
arubanetworkscx_8325-cpe:2.3:h:arubanetworks:cx_8325:-:*:*:*:*:*:*:*
arubanetworkscx_8360-cpe:2.3:h:arubanetworks:cx_8360:-:*:*:*:*:*:*:*
arubanetworkscx_8400-cpe:2.3:h:arubanetworks:cx_8400:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Aruba AOS-CX firmware: 10.04.xxxx - versions prior to 10.04.3070, 10.05.xxxx - versions prior to 10.05.0070, 10.06.xxxx - versions prior to 10.06.0110, 10.07.xxxx - versions prior to 10.07.0001"
      }
    ]
  }
]

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

33.8%

Related for CVE-2021-29148