ID

VAR-201812-0630


CVE

CVE-2018-7080


TITLE

Aruba Access point Vulnerabilities related to security functions

Trust: 0.8

sources: JVNDB: JVNDB-2018-014398

DESCRIPTION

A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986. Aruba Access point Contains vulnerabilities related to security features.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Texas Instruments Bluetooth Low Energy Chips are prone to an remote code-execution vulnerability. Successfully exploiting this issue will allow an attackers to execute arbitrary code. Aruba AP-3xx and others are wireless access point devices of Aruba Networks

Trust: 1.98

sources: NVD: CVE-2018-7080 // JVNDB: JVNDB-2018-014398 // BID: 105814 // VULHUB: VHN-137112

AFFECTED PRODUCTS

vendor:arubanetworksmodel:arubaosscope:ltversion:8.2.2.2

Trust: 1.0

vendor:arubanetworksmodel:arubaosscope:ltversion:8.3.0.4

Trust: 1.0

vendor:arubanetworksmodel:arubaosscope:gteversion:6.5.3.0

Trust: 1.0

vendor:arubanetworksmodel:203rpscope:eqversion: -

Trust: 1.0

vendor:arubanetworksmodel:arubaosscope:gteversion:6.4.4.0

Trust: 1.0

vendor:arubanetworksmodel:arubaosscope:ltversion:6.5.4.9

Trust: 1.0

vendor:arubanetworksmodel:203rscope:eqversion: -

Trust: 1.0

vendor:arubanetworksmodel:ap-300 series access pointsscope:eqversion: -

Trust: 1.0

vendor:arubanetworksmodel:ap-300 series instant access pointsscope:eqversion: -

Trust: 1.0

vendor:arubanetworksmodel:arubaosscope:ltversion:6.4.4.20

Trust: 1.0

vendor:arubanetworksmodel:arubaosscope:gteversion:8.0.0.0

Trust: 1.0

vendor:arubanetworksmodel:arubaosscope:ltversion:6.5.3.9

Trust: 1.0

vendor:arubanetworksmodel:arubaosscope:gteversion:6.5.4.0

Trust: 1.0

vendor:arubanetworksmodel:arubaosscope:gteversion:8.3.0.0

Trust: 1.0

vendor:arubamodel:203rscope: - version: -

Trust: 0.8

vendor:arubamodel:203rpscope: - version: -

Trust: 0.8

vendor:arubamodel:300 series access pointsscope: - version: -

Trust: 0.8

vendor:arubamodel:instant apscope: - version: -

Trust: 0.8

vendor:arubamodel:arubaosscope: - version: -

Trust: 0.8

vendor:timodel:cc2650scope:eqversion:0

Trust: 0.3

vendor:timodel:cc2642rscope:eqversion:0

Trust: 0.3

vendor:timodel:cc2640r2fscope:eqversion:0

Trust: 0.3

vendor:timodel:cc2640scope:eqversion:0

Trust: 0.3

vendor:timodel:cc2541scope:eqversion:0

Trust: 0.3

vendor:timodel:cc2540scope:eqversion:0

Trust: 0.3

vendor:arubanetworksmodel:iap-3xxscope:eqversion:0

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:8.3.0

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:8.1.0.4

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:8.1.0.3

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:8.0

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:6.5.4.2

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:6.5.4.1

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:6.5.4.0

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:6.5.3.3

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:6.5.3.2

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:6.5.3.0

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:6.4.4.16

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:6.4.4.15

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:eqversion:6.4.4.0

Trust: 0.3

vendor:arubanetworksmodel:ap-3xxscope:eqversion:0

Trust: 0.3

vendor:arubanetworksmodel:ap-203rpscope:eqversion:0

Trust: 0.3

vendor:arubanetworksmodel:ap-203rscope:eqversion:0

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:neversion:8.3.0.4

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:neversion:8.2.2.2

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:neversion:6.5.4.9

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:neversion:6.5.3.9

Trust: 0.3

vendor:arubanetworksmodel:arubaosscope:neversion:6.4.4.20

Trust: 0.3

sources: BID: 105814 // JVNDB: JVNDB-2018-014398 // NVD: CVE-2018-7080

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-7080
value: HIGH

Trust: 1.0

NVD: CVE-2018-7080
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201811-090
value: HIGH

Trust: 0.6

VULHUB: VHN-137112
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-7080
severity: MEDIUM
baseScore: 5.4
vectorString: AV:A/AC:M/AU:N/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 5.5
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-137112
severity: MEDIUM
baseScore: 5.4
vectorString: AV:A/AC:M/AU:N/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 5.5
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-7080
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.6
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-137112 // JVNDB: JVNDB-2018-014398 // CNNVD: CNNVD-201811-090 // NVD: CVE-2018-7080

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-254

Trust: 0.9

sources: VULHUB: VHN-137112 // JVNDB: JVNDB-2018-014398 // NVD: CVE-2018-7080

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-201811-090

TYPE

security feature problem

Trust: 0.6

sources: CNNVD: CNNVD-201811-090

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014398

PATCH

title:ARUBA-PSA-2018-006url:https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-006.txt

Trust: 0.8

title:Texas Instruments Bluetooth Low Energy Chips Enter the fix for the verification vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=86610

Trust: 0.6

sources: JVNDB: JVNDB-2018-014398 // CNNVD: CNNVD-201811-090

EXTERNAL IDS

db:NVDid:CVE-2018-7080

Trust: 2.8

db:BIDid:105814

Trust: 2.0

db:JVNDBid:JVNDB-2018-014398

Trust: 0.8

db:CNNVDid:CNNVD-201811-090

Trust: 0.7

db:VULHUBid:VHN-137112

Trust: 0.1

sources: VULHUB: VHN-137112 // BID: 105814 // JVNDB: JVNDB-2018-014398 // CNNVD: CNNVD-201811-090 // NVD: CVE-2018-7080

REFERENCES

url:https://www.arubanetworks.com/assets/alert/aruba-psa-2018-006.txt

Trust: 2.0

url:http://www.securityfocus.com/bid/105814

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7080

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7080

Trust: 0.8

url:http://www.arubanetworks.com/

Trust: 0.3

url:http://www.ti.com/

Trust: 0.3

url:https://armis.com/bleedingbit/

Trust: 0.3

sources: VULHUB: VHN-137112 // BID: 105814 // JVNDB: JVNDB-2018-014398 // CNNVD: CNNVD-201811-090 // NVD: CVE-2018-7080

CREDITS

Armis

Trust: 0.9

sources: BID: 105814 // CNNVD: CNNVD-201811-090

SOURCES

db:VULHUBid:VHN-137112
db:BIDid:105814
db:JVNDBid:JVNDB-2018-014398
db:CNNVDid:CNNVD-201811-090
db:NVDid:CVE-2018-7080

LAST UPDATE DATE

2024-11-23T22:30:10.495000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-137112date:2020-08-24T00:00:00
db:BIDid:105814date:2018-11-01T00:00:00
db:JVNDBid:JVNDB-2018-014398date:2019-03-19T00:00:00
db:CNNVDid:CNNVD-201811-090date:2020-08-25T00:00:00
db:NVDid:CVE-2018-7080date:2024-11-21T04:11:37.020

SOURCES RELEASE DATE

db:VULHUBid:VHN-137112date:2018-12-07T00:00:00
db:BIDid:105814date:2018-11-01T00:00:00
db:JVNDBid:JVNDB-2018-014398date:2019-03-19T00:00:00
db:CNNVDid:CNNVD-201811-090date:2018-11-06T00:00:00
db:NVDid:CVE-2018-7080date:2018-12-07T21:29:01.390