Vulnerability Name:

CVE-2021-41005 (CCN-224595)

Assigned:2021-09-13
Published:2022-04-07
Updated:2022-04-20
Summary:A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-41005

Source: XF
Type: UNKNOWN
hpe-aruba-cve202141005-dos(224595)

Source: CCN
Type: HPESBNW04270 rev.1
HPE Aruba Instant On 1930 switch, Denial of Service

Source: MISC
Type: Mitigation, Vendor Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04270en_us

Vulnerable Configuration:Configuration 1:
  • cpe:/o:hpe:aruba_instant_on_1930_8g_2sfp_firmware:*:*:*:*:*:*:*:* (Version < 1.0.7.0)
  • AND
  • cpe:/h:hpe:aruba_instant_on_1930_8g_2sfp:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:hpe:aruba_instant_on_1930_8g_class4_poe_2sfp_124w_firmware:*:*:*:*:*:*:*:* (Version < 1.0.7.0)
  • AND
  • cpe:/h:hpe:aruba_instant_on_1930_8g_class4_poe_2sfp_124w:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:hpe:aruba_instant_on_1930_48g_class4_poe_4sfp/sfp+_370w_firmware:*:*:*:*:*:*:*:* (Version < 1.0.7.0)
  • AND
  • cpe:/h:hpe:aruba_instant_on_1930_48g_class4_poe_4sfp/sfp+_370w:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:hpe:aruba_instant_on_1930_48g_4sfp/sfp+_firmware:*:*:*:*:*:*:*:* (Version < 1.0.7.0)
  • AND
  • cpe:/h:hpe:aruba_instant_on_1930_48g_4sfp/sfp+:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:hpe:aruba_instant_on_1930_24g_class4_poe_4sfp/sfp+_370w_firmware:*:*:*:*:*:*:*:* (Version < 1.0.7.0)
  • AND
  • cpe:/h:hpe:aruba_instant_on_1930_24g_class4_poe_4sfp/sfp+_370w:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:hpe:aruba_instant_on_1930_24g_class4_poe_4sfp/sfp+_195w_firmware:*:*:*:*:*:*:*:* (Version < 1.0.7.0)
  • AND
  • cpe:/h:hpe:aruba_instant_on_1930_24g_class4_poe_4sfp/sfp+_195w:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:hpe:aruba_instant_on_1930_24g_4sfp/sfp+_firmware:*:*:*:*:*:*:*:* (Version < 1.0.7.0)
  • AND
  • cpe:/h:hpe:aruba_instant_on_1930_24g_4sfp/sfp+:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    hpe aruba instant on 1930 8g 2sfp firmware *
    hpe aruba instant on 1930 8g 2sfp -
    hpe aruba instant on 1930 8g class4 poe 2sfp 124w firmware *
    hpe aruba instant on 1930 8g class4 poe 2sfp 124w -
    hpe aruba instant on 1930 48g class4 poe 4sfp/sfp+ 370w firmware *
    hpe aruba instant on 1930 48g class4 poe 4sfp/sfp+ 370w -
    hpe aruba instant on 1930 48g 4sfp/sfp+ firmware *
    hpe aruba instant on 1930 48g 4sfp/sfp+ -
    hpe aruba instant on 1930 24g class4 poe 4sfp/sfp+ 370w firmware *
    hpe aruba instant on 1930 24g class4 poe 4sfp/sfp+ 370w -
    hpe aruba instant on 1930 24g class4 poe 4sfp/sfp+ 195w firmware *
    hpe aruba instant on 1930 24g class4 poe 4sfp/sfp+ 195w -
    hpe aruba instant on 1930 24g 4sfp/sfp+ firmware *
    hpe aruba instant on 1930 24g 4sfp/sfp+ -