ArubaOS / SSH Authentication Bypass

High Nessus Plugin ID 78510


The version of ArubaOS has an authentication bypass vulnerability.


The version of ArubaOS has an unspecified vulnerability that allows a remote attacker to obtain limited administrative privileges without valid credentials. The vulnerability affects access over SSH. However, access through WebUI and the serial port is not affected, and the vulnerability does not provide 'root' level access, although it could allow the following activities :

- Issue 'show' commands.

- Obtain encrypted password hashes for administrative accounts.

- View the running configuration.

- Add users to the internal user database with 'guest' rights.


Upgrade to / or downgrade to /

See Also

Plugin Details

Severity: High

ID: 78510

File Name: arubaos_auth_bypass_aid-10072014.nasl

Version: $Revision: 1.5 $

Type: remote

Family: Misc.

Published: 2014/10/16

Modified: 2017/04/28

Dependencies: 78509

Risk Information

Risk Factor: High


Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:arubanetworks:arubaos

Required KB Items: Host/ArubaNetworks/ArubaOS/version

Patch Publication Date: 2014/10/07

Vulnerability Publication Date: 2014/10/07

Reference Information

CVE: CVE-2014-7299

OSVDB: 112832