Description Preview
CVE-2018-7080 describes a vulnerability that exists in the firmware of embedded Bluetooth Low Energy (BLE) radios present in specific models of Aruba Access Points manufactured by Hewlett Packard Enterprise. If exploited, an attacker could install potentially malicious firmware onto the BLE radio of the affected access points, which could subsequently allow unauthorized access to the access point's console port. It is important to note that this vulnerability is only applicable if the BLE radio feature is enabled, as it is disabled by default in the affected devices. Additionally, Aruba products are not affected by a similar vulnerability identified as CVE-2018-16986.
Overview
- Affected Products: Aruba Access Points, including AP-3xx and IAP-3xx series, AP-203R, AP-203RP, and various versions of ArubaOS (6.4.4.x prior to 6.4.4.20, 6.5.3.x prior to 6.5.3.9, 6.5.4.x prior to 6.5.4.9, 8.x prior to 8.2.2.2, and 8.3.x prior to 8.3.0.4).
- Vulnerability Type: Remote access restriction bypass.
- Impact: An attacker could gain unauthorized access to the access point's console port.
- Default Configuration: The BLE radio is disabled by default, reducing the risk of exploitation unless explicitly enabled.
Remediation
To mitigate the risk associated with CVE-2018-7080, users of affected Aruba Access Points should:
- Update Firmware: Upgrade to the latest version of ArubaOS that addresses this vulnerability. Ensure that the firmware version is at least:
- ArubaOS 6.4.4.20 or later
- ArubaOS 6.5.3.9 or later
- ArubaOS 6.5.4.9 or later
- ArubaOS 8.2.2.2 or later
- ArubaOS 8.3.0.4 or later
- Disable BLE Radio: If not required, keep the BLE radio feature disabled to prevent potential exploitation.
- Monitor Access Points: Regularly check logs and monitor for any unauthorized access attempts.
References
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Health Care & Social AssistanceHealth Care & Social Assistance: Low
- Educational ServicesEducational Services: Low
- ManufacturingManufacturing: Low
- Public AdministrationPublic Administration: Low
- Retail TradeRetail Trade: Low
- Finance and InsuranceFinance and Insurance: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Transportation & WarehousingTransportation & Warehousing: Low
- Accommodation & Food ServicesAccommodation & Food Services: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- ConstructionConstruction: Low
- InformationInformation: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- MiningMining: Low
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- UtilitiesUtilities: Low
- Wholesale TradeWholesale Trade: Low