CVE Vulnerabilities

CVE-2022-37894

Published: Oct 07, 2022 | Modified: Nov 09, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.

Affected Software

Name Vendor Start Version End Version
Arubaos Arubanetworks 10.3.0.0 (including) 10.3.1.1 (excluding)
Instant Arubanetworks 6.4.0.0 (including) 6.4.4.8-4.2.4.21 (excluding)
Instant Arubanetworks 6.5.0.0 (including) 6.5.4.24 (excluding)
Instant Arubanetworks 8.6.0.0 (including) 8.6.0.19 (excluding)
Instant Arubanetworks 8.7.0.0 (including) 8.7.1.10 (excluding)
Instant Arubanetworks 8.10.0.0 (including) 8.10.0.2 (excluding)

References