Description
A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability.
Published: 2021-02-09
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-12052 A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability.
History

No history.

Subscriptions

Arubanetworks Aruba 2530ya Aruba 2530ya Firmware Aruba 2530yb Aruba 2530yb Firmware Aruba 2540 Aruba 2540 Firmware Aruba 2620 Aruba 2620 Firmware Aruba 2920 Aruba 2920 Firmware Aruba 2930f Aruba 2930f Firmware Aruba 2930m Aruba 2930m Firmware Aruba 3800 Aruba 3800 Firmware Aruba 3810m Aruba 3810m Firmware Aruba 5406r Zl2 Aruba 5406r Zl2 Firmware Aruba 5412r Zl2 Aruba 5412r Zl2 Firmware
Hpe 3500 3500 Firmware 3500 Yl 3500 Yl Firmware 6200 Yl 6200 Yl Firmware 8200 Zl 8200 Zl Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2024-08-03T19:56:10.491Z

Reserved: 2021-01-14T00:00:00.000Z

Link: CVE-2021-25141

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-09T17:15:14.780

Modified: 2024-11-21T05:54:25.993

Link: CVE-2021-25141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses