SB2021032923 - Improper Authentication in Aruba Instant
Published: March 29, 2021 Updated: May 14, 2021
Security Bulletin ID
SB2021032923
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Physical access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2019-5317)
The vulnerability allows a local attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. An attacker with physical access can bypass authentication mechanisms and gain access to the Aruba Instant command line interface.
Remediation
Install update from vendor's website.