CVE-2018-7080

UnknownEPSS 0.64%

Last modified

CVE-2018-7080 is a vulnerability of currently unknown severity. A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. EPSS estimates a 0.64% chance of exploitation in the next 30 days.

Description

A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986.

Metrics

EPSS Probability
0.64%

45.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
ArubanetworksArubaos>= 6.4.4.0, < 6.4.4.20
ArubanetworksArubaos>= 6.5.3.0, < 6.5.3.9
ArubanetworksArubaos>= 6.5.4.0, < 6.5.4.9
ArubanetworksArubaos>= 8.0.0.0, < 8.2.2.2
ArubanetworksArubaos>= 8.3.0.0, < 8.3.0.4
Arubanetworks203rp FirmwareAll versions
Arubanetworks203r FirmwareAll versions
ArubanetworksAp-300 Series Access Points FirmwareAll versions
ArubanetworksAp-300 Series Instant Access Points FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-7080?
A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986.
How severe is CVE-2018-7080?
Severity scoring for CVE-2018-7080 is pending analysis. The EPSS model estimates a 0.64% probability of exploitation in the next 30 days.
How do I fix CVE-2018-7080?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-7080?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST