OS Command Injection in Aruba Instant - CVE-2021-37727
Published: October 7, 2021 / Updated: November 18, 2021
Vulnerability identifier: #VU57132
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37727
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to escalate privileges on the system.
The vulnerability exists due to improper input validation in the command line interface. A remote privileged user can pass specially crafted data to the application and execute arbitrary OS commands on the system.
Affected software
Aruba Instant
SCALANCE W1750D
SCALANCE W1750D
How to mitigate CVE-2021-37727
Install updates from vendor's website.
Aruba Instant - addressed in versions 6.4.4.8-4.2.4.19, 6.5.4.21, 8.5.0.13, 8.6.0.12, 8.7.1.4