Vulnerabilities > CVE-2018-7080 - Unspecified vulnerability in Arubanetworks products

047910
CVSS 5.4 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986.

Vulnerable Configurations

Part Description Count
OS
Arubanetworks
55
Hardware
Arubanetworks
4

The Hacker News

idTHN:8A584D8B16477D29452519523E98350A
last seen2018-11-01
modified2018-11-01
published2018-11-01
reporterThe Hacker News
sourcehttps://thehackernews.com/2018/11/bluetooth-chip-hacking.html
titleTwo New Bluetooth Chip Flaws Expose Millions of Devices to Remote Attacks