Vulnerabilities > CVE-2018-7080 - Unspecified vulnerability in Arubanetworks products

047910
CVSS 7.5 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
high complexity
arubanetworks

Summary

A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986.

Vulnerable Configurations

Part Description Count
OS
Arubanetworks
57
Hardware
Arubanetworks
4

The Hacker News

idTHN:8A584D8B16477D29452519523E98350A
last seen2018-11-01
modified2018-11-01
published2018-11-01
reporterThe Hacker News
sourcehttps://thehackernews.com/2018/11/bluetooth-chip-hacking.html
titleTwo New Bluetooth Chip Flaws Expose Millions of Devices to Remote Attacks