CVE-2020-7121
Last modified
CVE-2020-7121 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the LLDP (Link Layer Discovery Protocol) process in the switch. EPSS estimates a 0.99% chance of exploitation in the next 30 days.
Description
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the LLDP (Link Layer Discovery Protocol) process in the switch. This applies to firmware versions prior to 10.04.3021.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Cx 6200f Firmware | <= 10.04.3021 |
| Arubanetworks | Cx 6300 Firmware | <= 10.04.3021 |
| Arubanetworks | Cx 6400 Firmware | <= 10.04.3021 |
| Arubanetworks | Cx 8320 Firmware | <= 10.04.3021 |
| Arubanetworks | Cx 8325 Firmware | <= 10.04.3021 |
| Arubanetworks | Cx 8400 Firmware | <= 10.04.3021 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7121?
How severe is CVE-2020-7121?
How do I fix CVE-2020-7121?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-7115The ClearPass Policy Manager web interface is affected by a …9.8
- CVE-2020-7116The ClearPass Policy Manager WebUI administrative interface …7.2
- CVE-2020-7117The ClearPass Policy Manager WebUI administrative interface …7.2
- CVE-2020-7118Rejected reason: CVE was unused by HPE.
- CVE-2020-7119A vulnerability exists in the Aruba Analytics and Location E…4.9
- CVE-2020-7120A local authenticated buffer overflow vulnerability was disc…5.3
- CVE-2020-7122Two memory corruption vulnerabilities in the Aruba CX Switch…7.5
- CVE-2020-7123A local escalation of privilege vulnerability was discovered…7.8
- CVE-2020-7124A remote unauthorized access vulnerability was discovered in…9.8
- CVE-2020-7125A remote escalation of privilege vulnerability was discovere…8.8
- CVE-2020-7126A remote server-side request forgery (ssrf) vulnerability wa…5.8
- CVE-2020-7127A remote unauthenticated arbitrary code execution vulnerabil…9.8
Are you affected by CVE-2020-7121?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
