« Volver al listado

CVE-2021-34618

Estado: ModificadaMedia (6.5)—

A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.4.x: All versions; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-34618",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.3,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Aruba Instant Access Points",
          "versions": [
            {
              "status": "affected",
              "version": "Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below"
            },
            {
              "status": "affected",
              "version": "Aruba Instant 6.5.x: 6.5.4.18 and below"
            },
            {
              "status": "affected",
              "version": "Aruba Instant 8.3.x: 8.3.0.14 and below"
            },
            {
              "status": "affected",
              "version": "Aruba Instant 8.4.x: All versions"
            },
            {
              "status": "affected",
              "version": "Aruba Instant 8.5.x: 8.5.0.11 and below"
            },
            {
              "status": "affected",
              "version": "Aruba Instant 8.6.x: 8.6.0.7 and below"
            },
            {
              "status": "affected",
              "version": "Aruba Instant 8.7.x: 8.7.1.1 and below"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-07-19T20:15:08.743",
  "references": [
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-007.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-007.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.4.x: All versions; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability."
    },
    {
      "lang": "es",
      "value": "Se ha detectado una vulnerabilidad de denegación de servicio (DoS) remota en algunos productos Aruba Instant Access Point (IAP) en versiones: Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 y posteriores; Aruba Instant 6.5.x: 6.5.4.18 y posteriores; Aruba Instant 8.3.x: 8.3.0.14 y posteriores; Aruba Instant 8.4.x: Todas las versiones; Aruba Instant 8.5.x: 8.5.0.11 e inferior; Aruba Instant 8.6.x: 8.6.0.7 e inferior; Aruba Instant 8.7.x: 8.7.1.1 e inferior. Aruba ha publicado parches para Aruba Instant que solucionan esta vulnerabilidad de seguridad"
    }
  ],
  "lastModified": "2026-06-17T03:56:14.440",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:aruba:aruba_instant:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71A2CB8D-2ABD-42FB-9BC5-B557EE760DD4",
              "versionEndIncluding": "6.4.4.8-4.2.4.18",
              "versionStartIncluding": "6.4.0"
            },
            {
              "criteria": "cpe:2.3:h:aruba:aruba_instant:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9FA09F6-0F0B-4377-887E-71221A29FCEC",
              "versionEndIncluding": "6.5.4.18",
              "versionStartIncluding": "6.5.0"
            },
            {
              "criteria": "cpe:2.3:h:aruba:aruba_instant:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "514796DB-052A-4B25-A80A-2EEAF35FC8EF",
              "versionEndIncluding": "8.3.0.14",
              "versionStartIncluding": "8.3.0"
            },
            {
              "criteria": "cpe:2.3:h:aruba:aruba_instant:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "229C9025-98BC-49E3-BF1B-8B066E4D430B",
              "versionEndIncluding": "8.5.0.11",
              "versionStartIncluding": "8.4.0"
            },
            {
              "criteria": "cpe:2.3:h:aruba:aruba_instant:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAAE46EF-A87B-4870-BE44-D43035588AA5",
              "versionEndIncluding": "8.6.0.7",
              "versionStartIncluding": "8.6.0"
            },
            {
              "criteria": "cpe:2.3:h:aruba:aruba_instant:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16A0DDA5-960C-4C51-A941-47D3B793EC4C",
              "versionEndIncluding": "8.7.1.1",
              "versionStartIncluding": "8.7.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}