-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Aruba Product Security Advisory =============================== Advisory ID: Aruba - psa -2021-002 CVE: CVE-2021-25141发布日期:2021-Feb-05状态:确认修订:1HPE and Aruba L2/L3 switch, Local Denial of Service (DoS) Overview ========在某些HPE和Aruba L2/L3交换机固件中发现了安全漏洞。在用户提供给交换机管理接口的信息中,由于对意外数据类型处理不当而导致的数据处理错误已被识别出来。数据处理错误可能被利用来导致交换机管理界面崩溃或重新启动,并且/或者交换机本身可能导致本地拒绝服务(DoS)。用户必须具有管理员权限才能利用此漏洞。CVE-2021-25141严重程度:中CVSSv3总分:4.2 CVSS矢量:CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H受影响产品================= SUPPORTED SOFTWARE VERSIONS*:只列出受影响的版本。阿鲁巴岛5400 r zl2开关系列- KB.16.10.0012阿鲁巴之前3810系列开关之前KB.16.10.0012阿鲁巴岛2930开关系列- WC.16.10.0012阿鲁巴之前2930 f系列开关之前WC.16.10.0012阿鲁巴岛2920开关系列- WB.16.10.0011阿鲁巴之前2540开关系列之前YC.16.10.0012阿鲁巴岛2530开关系列阿鲁巴岛2530丫之前YA.16.10.0012阿鲁巴岛2530年之前yb YB.16.10.0012阿鲁巴岛5400 zl系列开关-前K.16.02.0032阿鲁巴岛3800开关系列- KA.16.04.0022阿鲁巴之前2620开关系列之前RA.16.04.0022 HPE 8200 zl系列开关-前K.15.18.0024 HPE 6200 yl系列开关-前K.15.18.0024 HPE 3500年和3500年yl系列开关——之前to K.16.02.0032 Resolution ========== HPE Aruba has released software updates to resolve this vulnerability in certain HPE and Aruba L2/L3 switch products. Please visit the Aruba Support Portal or the HPE My Networking Portal to download the latest firmware and software updates for the following products: Aruba 5400 zl2 Switch Series - KB.16.10.0012 Aruba 3810M Switch Series - KB.16.10.0012 Aruba 2930M Switch Series - WC.16.10.0012 Aruba 2930F Switch Series - WC.16.10.0012 Aruba 2920 Switch Series - WB.16.10.0011 Aruba 2540 Switch Series - YC.16.10.0012 Aruba 2530YB Switch Series - YB.16.10.0012 Aruba 2530YA Switch Series - YA.16.10.0012 Aruba 5400 zl Switch Series - K.16.02.0032 Aruba 3800 Switch Series - KA.16.04.0022 Aruba 2620 Switch Series - RA.16.04.0022 HPE 8200 zl Switch Series - K.15.18.0024 HPE 6200 yl Switch Series - K.15.18.0024 HPE 3500 and 3500 yl Switch Series - K.16.02.0032 Workaround ========== None. Revision History ================ Revision 1 / 2021-Feb-05 / Initial release Aruba SIRT Security Procedures ============================== Complete information on reporting security vulnerabilities in Aruba Networks products, obtaining assistance with security incidents is available at: //www.nexbus-cng.com/support-services/security-bulletins/ For reporting *NEW* Aruba Networks security issues, email can be sent to aruba-sirt(at)hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: //www.nexbus-cng.com/support-services/security-bulletins/ (c) Copyright 2021 by Aruba, a Hewlett Packard Enterprise company. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information. -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEMd5pP5EnbG7Y0fo5mP4JykWFhtkFAmAZ7ggACgkQmP4JykWF htmWmgf/RktnApR1zkP8xXaBESDLGh6hT3PwPtl4P0CJ/Z3Ac2KofqEH/9U9wZH5 veExEofRPa8evKHPA4xj8aqk20kREg7xhACbY+465yigeMkKRyaOyAF6sdAWt0Yu QKG1fI2uhwtlUykBdGOJ/MUlLXUkaYXh5TbWccaeRwux5VXBNPsqfXeigxwyolIR myQY1HxrbqUyiQUzaCJ9jH14weLp/Iaj75pMzWy+MIjsL1eYbsNy2AHgytPoRWM1 6DP/mv+q1MjJWLpEToaTVNJRG+SQvgwednOIowtBSMgUljrXkUqkx38kLnL7J7MI 6Jdw0e5u0XvzGcd1QkHYL/pQr87vAw== =S4Xs -----END PGP SIGNATURE-----
Baidu