HPE Aruba Networking product security update advisory

Overview

 

HPE Aruba Networking has released an update to address a vulnerability in its products. users of affected versions are advised to update to the latest version.

 

Affected Products

 

ArubaOS

  • up to and including 10.5.1.0
  • up to and including 10.4.1.0
  • up to and including 8.11.2.1
  • up to and including 8.10.0.10

 

Resolved Vulnerabilities

 

Unauthenticated Remote Code Execution Buffer Overflow Vulnerability in ArubaOS on HPE Aruba Networking (CVE-2024-26304) [2][3]

Unauthenticated Remote Code Execution Buffer Overflow Vulnerability in ArubaOS in HPE Aruba Networking (CVE-2024-26305) [2][3]

Unauthenticated Remote Code Execution Buffer Overflow Vulnerability in ArubaOS on HPE Aruba Networking (CVE-2024-33511) [2][3]

Unauthenticated Remote Code Executable Buffer Overflow Vulnerability in ArubaOS on HPE Aruba Networking (CVE-2024-33512) [2][3]

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

ArubaOS versions 10.6.0.0, 10.5.1.1, 10.4.1.1, 8.11.2.2, and 8.10.0.11

 

Referenced Sites

 

[1] https://www.arubanetworks.com/ko/support-services/security-bulletins/

[2] https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-004.txt

[3] https://www.arubanetworks.com/assets/alert/csaf/aruba-psa-2024-004.json