
Ukraine Targets Outdated Military Equipment in Ongoing Conflict
Section: Politics
Hewlett Packard Enterprise (HPE) has announced critical security updates addressing vulnerabilities in various network devices under its Aruba brand. Attackers could potentially exploit these weaknesses to inject malicious code into affected devices, including access points, mobility controllers, conductors, and gateways.
The more significant vulnerabilities identified primarily affect Aruba Mobility Conductors, Controllers, and Gateways running on AOS-10 and AOS-8 operating systems. The implications of these security loopholes are severe, with potential outcomes including remote execution of arbitrary code, command execution, unauthorized file downloads, file modifications, cross-site scripting (XSS), and unauthorized command execution.
A total of four vulnerabilities have been highlighted in the initial security advisory. The web-based management interface allows authenticated users to write files, enabling them to inject and execute code (CVE-2025-27082, CVSS score 7.2, categorized as 'high risk'). Additionally, it permits the injection of commands (CVE-2025-27083, CVSS score 7.2, also 'high risk'). Furthermore, the captive portal within the web management interface is susceptible to cross-site scripting attacks (CVE-2025-27084, CVSS score 5.4, categorized as 'medium risk'). Authenticated users can also download arbitrary files from vulnerable devices (CVE-2025-27085, CVSS score 4.9, categorized as 'medium risk').
To rectify these issues, HPE has released firmware versions 10.7.1.1, 10.4.1.7, 8.12.0.4, and 8.10.0.16. It is important to note that older versions of the software affected by these vulnerabilities have reached their end of support and will not receive further updates.
In a separate advisory, HPE outlined vulnerabilities in Aruba Access Points, where authenticated attackers can execute commands remotely (CVE-2025-27078, CVSS score 6.5, categorized as 'medium risk'). They can also create arbitrary files on the devices, allowing for code injection and execution (CVE-2025-27079, CVSS score 6.0, categorized as 'medium risk'). Firmware versions AOS-10 10.7.0.2, 10.4.1.6, and AOS-8 Instant 8.12.0.4 and 8.10.0.16 have been released to address these security vulnerabilities.
Last week, HPE addressed security flaws in the VPN functionality of Aruba, which allowed potential breaches via the HPE Aruba Networking Virtual Intranet Access Client.
Section: Politics
Section: News
Section: News
Section: Health
Section: News
Section: News
Section: Travel
Section: News
Section: News
Section: Politics
Health Insurance in Germany is compulsory and sometimes complicated, not to mention expensive. As an expat, you are required to navigate this landscape within weeks of arriving, so check our FAQ on PKV. For our guide on resources and access to agents who can give you a competitive quote, try our PKV Cost comparison tool.
Germany is famous for its medical expertise and extensive number of hospitals and clinics. See this comprehensive directory of hospitals and clinics across the country, complete with links to their websites, addresses, contact info, and specializations/services.
Join us for an exciting theatrical experience on Saturday, May 10, 2025, from 19:30 to 22:00 at the Münchner Kammerspiele - Werkraum. This performance, directed by Melina Dressler, is a directorial exercise inspired by Heiner Müller's 'Quartett' and incorporates texts by Michel Foucault. The...
No comments yet. Be the first to comment!