
Log4J Vulnerabilities - Aruba Resolutions (Updated to 20 Dec 2021)
The information provided below is referred from https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-019.txt, https://sirt.arubanetworks.com/mailman/listinfo/security-alerts_sirt.arubanetworks.com, https://www.arubanetworks.com/website/techdocs/sdwan/docs/advisories/media/security_advisory_notice_apache_log4j2_cve_2021_44228.pdf and https://www.arubanetworks.com/support-services/security-bulletins/.
- Not provided
- Critical
Since the discovery of these vulnerabilities, Aruba SIRT has been closely monitoring these threats and how they may affect Aruba products. Aruba SIRT consulted with the product teams, and Aruba Threat Labs performed various tests using POC (Proof of Concept) code against products.
Although some Aruba products use the log4j library, none of them use it in a way that makes them vulnerable to CVE-2021-44228 and CVE-2021-45046. The conclusion of the investigation is that the products listed in the “Unaffected Products” tab are not vulnerable to CVE-2021-44228 and CVE-2021-45046.
- All Silver Peak Orchestrator and legacy GMS products.
- AirWave Management Platform
- Aruba Analytics and Location Engine
- Aruba Central / Central On-Premises
- Aruba ClearPass Policy Manager
- Aruba Instant / Aruba Instant Access Points
- Aruba Instant On
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- Aruba NetEdit
- Aruba User Experience Insight (UXI)
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- ArubaOS-CX Switches
- ArubaOS-S Switches
- HP ProCurve Switches
- Aruba VIA Client
To receive Security Advisory updates, subscribe to notifications at https://sirt.arubanetworks.com/mailman/listinfo/security-alerts_sirt.arubanetworks.com Complete information on reporting security vulnerabilities in Aruba Networks products and obtaining assistance with security incidents is available at:
https://www.arubanetworks.com/support-services/security-bulletins/
For reporting *NEW* Aruba Networks security issues, email can be sent to aruba-sirt(at)hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at:
https://www.arubanetworks.com/support-services/security-bulletins/