A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.8.0.1, 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
2021-09-07T13:15:07.940
2024-11-21T06:15:48.647
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:N/I:C/A:C
8.6
9.2
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | arubanetworks | sd-wan | < 2.2.0.4 | Yes |
Operating System | arubanetworks | arubaos | < 8.3.0.15 | Yes |
Operating System | arubanetworks | arubaos | < 8.5.0.12 | Yes |
Operating System | arubanetworks | arubaos | < 8.6.0.8 | Yes |
Operating System | arubanetworks | arubaos | < 8.7.1.2 | Yes |
Operating System | arubanetworks | arubaos | < 8.8.0.1 | Yes |
Operating System | siemens | scalance_w1750d_firmware | < 8.7.1.3 | Yes |
Hardware | siemens | scalance_w1750d | - | No |