High severity7.5NVD Advisory· Published Dec 7, 2018· Updated Jun 17, 2026
CVE-2018-7080
CVE-2018-7080
Description
A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986.
Affected products
8- cpe:2.3:o:arubanetworks:203r_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:arubanetworks:203rp_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:arubanetworks:ap-300_series_access_points_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:arubanetworks:ap-300_series_instant_access_points_firmware:-:*:*:*:*:*:*:*
- Hewlett Packard Enterprise/Aruba Access Pointsv5Range: AP-3xx and IAP-3xx series access points, AP-203R, AP-203RP, ArubaOS 6.4.4.x prior to 6.4.4.20, ArubaOS 6.5.3.x prior to 6.5.3.9, ArubaOS 6.5.4.x prior to 6.5.4.9, ArubaOS 8.x prior to 8.2.2.2, ArubaOS 8.3.x prior to 8.3.0.4
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/105814nvdThird Party AdvisoryVDB Entry
- www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-006.txtnvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.