A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x: all versions prior to 8.8.0.0. Aruba has released patches for ArubaOS that address this security vulnerability.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-016.txt | vendor advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-280624.pdf | mitigation vendor advisory |