Aruba Instant command execution

Added: 07/28/2021

Background

Aruba Instant is a controllerless wi-fi solution.

Problem

The combination of several different vulnerabilities in Aruba Instant could allow remote attackers to execute arbitrary commands by sending specially crafted web requests.

Resolution

Upgrade to Aruba Instant version 6.4.4.8-4.2.4.19, 6.5.4.19, 8.3.0.15, 8.5.0.12, 8.6.0.8, or 8.7.1.2 or higher.

References

https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-007.txt

Back to exploit index