CVE-2018-7080
Last modified
CVE-2018-7080 is a vulnerability of currently unknown severity. A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Arubaos | >= 6.4.4.0, < 6.4.4.20 |
| Arubanetworks | Arubaos | >= 6.5.3.0, < 6.5.3.9 |
| Arubanetworks | Arubaos | >= 6.5.4.0, < 6.5.4.9 |
| Arubanetworks | Arubaos | >= 8.0.0.0, < 8.2.2.2 |
| Arubanetworks | Arubaos | >= 8.3.0.0, < 8.3.0.4 |
| Arubanetworks | 203rp Firmware | All versions |
| Arubanetworks | 203r Firmware | All versions |
| Arubanetworks | Ap-300 Series Access Points Firmware | All versions |
| Arubanetworks | Ap-300 Series Instant Access Points Firmware | All versions |
References
- http://www.securityfocus.com/bid/105814Third Party Advisory, VDB Entry
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-006.txtMitigation, Vendor Advisory
- http://www.securityfocus.com/bid/105814Third Party Advisory, VDB Entry
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-006.txtMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7080?
How severe is CVE-2018-7080?
How do I fix CVE-2018-7080?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7074A remote code execution vulnerability was identified in HPE …
- CVE-2018-7075A remote cross-site scripting (XSS) vulnerability was identi…
- CVE-2018-7076A remote code execution vulnerability was identified in HPE …
- CVE-2018-7077A security vulnerability in HPE XP P9000 Command View Advanc…
- CVE-2018-7078A remote code execution was identified in HPE Integrated Lig…
- CVE-2018-7079Aruba ClearPass Policy Manager guest authorization failure. …
- CVE-2018-7081A remote code execution vulnerability is present in network-…9.8
- CVE-2018-7082A command injection vulnerability is present in Aruba Instan…7.2
- CVE-2018-7083If a process running within Aruba Instant crashes, it may le…
- CVE-2018-7084A command injection vulnerability is present that permits an…9.8
- CVE-2018-7085Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-7086Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2018-7080?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
