CVE-2021-25141
Estado: ModificadaMedia (4.4)—
A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 4.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.30%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (15)
Arubanetworks — Aruba 2530ya FirmwareArubanetworks — Aruba 2530yb FirmwareArubanetworks — Aruba 2540 FirmwareArubanetworks — Aruba 2620 FirmwareArubanetworks — Aruba 2920 FirmwareArubanetworks — Aruba 2930f FirmwareArubanetworks — Aruba 2930m FirmwareArubanetworks — Aruba 3800 FirmwareArubanetworks — Aruba 3810m FirmwareArubanetworks — Aruba 5406r ZL2 FirmwareArubanetworks — Aruba 5412r ZL2 FirmwareHPE — 3500 FirmwareHPE — 3500 YL FirmwareHPE — 6200 YL FirmwareHPE — 8200 ZL Firmware
CWE
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-25141",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "security-alert@hpe.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Aruba 5400R zl2 Switch Series; Aruba 2930F Switch Series; Aruba 2920 Switch Series; Aruba 2930M Switch Series; Aruba 2530 Switch Series; Aruba 2540 Switch Series; Aruba 3800 Switch Series; HPE 3500 and 3500 yl Switch Series; Aruba 3810M Switch Series; HPE 8200 zl Switch Series; Aruba 2620 Switch Series; Aruba 5400 zl Switch Series; HPE 6200 yl Switch Series",
"versions": [
{
"status": "affected",
"version": "Prior to KB.16.10.0012"
},
{
"status": "affected",
"version": "- Prior to WC.16.10.0012"
},
{
"status": "affected",
"version": "- Prior to WB.16.10.0011"
},
{
"status": "affected",
"version": "- Aruba 2530YA prior to YA.16.10.0012 / Aruba 2530YB prior YB.16.10.0012"
},
{
"status": "affected",
"version": "- Prior to YC.16.10.0012"
},
{
"status": "affected",
"version": "- Prior to KA.16.04.0022"
},
{
"status": "affected",
"version": "- Prior to K.16.02.0032"
},
{
"status": "affected",
"version": "- Prior to KB.16.10.0012"
},
{
"status": "affected",
"version": "- Prior to K.15.18.0024"
},
{
"status": "affected",
"version": "- Prior to RA.16.04.0022"
}
]
}
]
}
],
"published": "2021-02-09T17:15:14.780",
"references": [
{
"url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04082en_us",
"tags": [
"Third Party Advisory"
],
"source": "security-alert@hpe.com"
},
{
"url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04082en_us",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad de seguridad en determinado firmware del switch HPE y Aruba L2/L3. Se identificó un error de procesamiento de datos debido al manejo inapropiado de un tipo de datos inesperado en la información suministrada por el usuario a la interfaz de administración del switch. El error de procesamiento de datos podría ser explotado para causar un bloqueo o reinicio en la interfaz de administración del switch y/o posiblemente el propio switch, conllevando a una denegación de servicio (DoS) local. El usuario debe tener privilegios de administrador para explotar esta vulnerabilidad"
}
],
"lastModified": "2026-06-17T03:41:32.133",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_5406r_zl2_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "972DC214-38A9-4FD2-B711-F9DDEB728EDB",
"versionEndExcluding": "kb.16.10.0012"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_5406r_zl2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8E982204-9ADC-4242-86C2-A407D6EA7DB0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_5412r_zl2_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B97B63E2-2EB1-41FB-A4F5-50E9E9569B6C",
"versionEndExcluding": "kb.16.10.0012"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_5412r_zl2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8549CD94-50E2-4615-94C2-D76FADFBA3AC"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_3810m_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA016A24-FC1F-4F47-AA50-874251107CF5",
"versionEndExcluding": "kb.16.10.0012"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_3810m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F3CE933B-68BA-45BA-81BD-95D873B858B1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_2930m_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F800D447-86D0-4435-9337-5B0D55E96F15",
"versionEndExcluding": "wc.16.10.0012"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_2930m:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2561E158-FB61-4FFD-B680-DADF7BC2C6D1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_2930f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48B6242A-87BC-48AA-9546-BA1FFF6E507C",
"versionEndExcluding": "wc.16.10.0012"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_2930f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "97C4FCD2-BB70-4848-B08A-223B5C3467BB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_2920_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84310DE6-B19A-4091-BA29-6BDF6EAE3C31",
"versionEndExcluding": "wb.16.10.0011"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_2920:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B1782D4A-AD68-4BD2-8453-EE22BCF2DC99"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_2540_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "590322F9-884D-4598-B222-D04E13AE2350",
"versionEndExcluding": "yc.16.10.0012"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_2540:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FDEDD15E-289E-4B15-8620-547EA19CAEE7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_2530ya_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1B21AAC-2F95-4EE9-9DFD-2864E0AD5172",
"versionEndExcluding": "ya.16.10.0012"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_2530ya:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B8251986-B9F2-4345-A4D7-EB3737F12AE0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_3800_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80404698-66D6-4649-AF49-B37EF53CC220",
"versionEndExcluding": "ka.16.04.0022"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_3800:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "50450263-8198-4A93-A317-86B8A0485328"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_2620_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA814B89-CF8A-464F-BD47-7B18CBEA7881",
"versionEndExcluding": "ra.16.04.0022"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_2620:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7F10B7C2-A4A5-4EDC-B5CD-F645DF518125"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:8200_zl_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C07219AB-7F2C-4384-A029-F7DBC6330555",
"versionEndExcluding": "k.15.18.0024"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:8200_zl:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A726CBA0-CA79-4903-BD50-4455B7667C43"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:6200_yl_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1FE2140-4A8C-4C46-A899-B023E330634F",
"versionEndExcluding": "k.15.18.0024"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:6200_yl:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "147CA290-22E2-498E-B925-6D85F44823DE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:3500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12442248-51A1-40CD-A25B-DF347341B8FC",
"versionEndExcluding": "k.16.02.0032"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:3500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "28168255-648C-4D4B-A765-1F0DE777E3F0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:3500_yl_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "703F3FE8-21A7-4938-96B9-C4A838FCB6FE",
"versionEndExcluding": "k.16.02.0032"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:3500_yl:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "91BBD047-E3C6-4AEA-B7B8-7BC4600E4E6A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:aruba_2530yb_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "201787FA-8CAC-457A-B7CC-76575A0DF0F3",
"versionEndExcluding": "yb.16.10.0012"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:aruba_2530yb:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3D7A8F42-55C8-4A2B-8A34-1B1B8BE3BEDF"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security-alert@hpe.com"
}