Risques
- Atteinte à l'intégrité des données
- Atteinte à la confidentialité des données
- Contournement de la politique de sécurité
- Déni de service à distance
- Exécution de code arbitraire à distance
- Injection de code indirecte à distance (XSS)
- Injection SQL (SQLi)
- Élévation de privilèges
Systèmes affectés
- AOS-Switch (AOS-S) versions antérieures à AOS-S 16.11.0032
- ClearPass Policy Manager (CPPM) versions antérieures à CPPM 6.11.16
- ClearPass Policy Manager (CPPM) versions antérieures à CPPM 6.14.1
Résumé
De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
- Bulletin de sécurité HPE Aruba Networking HPESBNW05156 du 06 octobre 2026 https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05156.txt
- Bulletin de sécurité HPE Aruba Networking HPESBNW05158 du 06 octobre 2026 https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05158.txt
- Référence CVE CVE-2026-76741 https://www.cve.org/CVERecord?id=CVE-2026-76741
- Référence CVE CVE-2026-76742 https://www.cve.org/CVERecord?id=CVE-2026-76742
- Référence CVE CVE-2026-76743 https://www.cve.org/CVERecord?id=CVE-2026-76743
- Référence CVE CVE-2026-76744 https://www.cve.org/CVERecord?id=CVE-2026-76744
- Référence CVE CVE-2026-76745 https://www.cve.org/CVERecord?id=CVE-2026-76745
- Référence CVE CVE-2026-76746 https://www.cve.org/CVERecord?id=CVE-2026-76746
- Référence CVE CVE-2026-76747 https://www.cve.org/CVERecord?id=CVE-2026-76747
- Référence CVE CVE-2026-76748 https://www.cve.org/CVERecord?id=CVE-2026-76748
- Référence CVE CVE-2026-76749 https://www.cve.org/CVERecord?id=CVE-2026-76749
- Référence CVE CVE-2026-76750 https://www.cve.org/CVERecord?id=CVE-2026-76750
- Référence CVE CVE-2026-76751 https://www.cve.org/CVERecord?id=CVE-2026-76751
- Référence CVE CVE-2026-76752 https://www.cve.org/CVERecord?id=CVE-2026-76752
- Référence CVE CVE-2026-76753 https://www.cve.org/CVERecord?id=CVE-2026-76753
- Référence CVE CVE-2026-76754 https://www.cve.org/CVERecord?id=CVE-2026-76754
- Référence CVE CVE-2026-79794 https://www.cve.org/CVERecord?id=CVE-2026-79794
- Référence CVE CVE-2026-79796 https://www.cve.org/CVERecord?id=CVE-2026-79796
- Référence CVE CVE-2026-79797 https://www.cve.org/CVERecord?id=CVE-2026-79797
- Référence CVE CVE-2026-79798 https://www.cve.org/CVERecord?id=CVE-2026-79798
- Référence CVE CVE-2026-79799 https://www.cve.org/CVERecord?id=CVE-2026-79799
- Référence CVE CVE-2026-79800 https://www.cve.org/CVERecord?id=CVE-2026-79800
- Référence CVE CVE-2026-79801 https://www.cve.org/CVERecord?id=CVE-2026-79801
- Référence CVE CVE-2026-79802 https://www.cve.org/CVERecord?id=CVE-2026-79802
- Référence CVE CVE-2026-79803 https://www.cve.org/CVERecord?id=CVE-2026-79803
- Référence CVE CVE-2026-79805 https://www.cve.org/CVERecord?id=CVE-2026-79805
- Référence CVE CVE-2026-79806 https://www.cve.org/CVERecord?id=CVE-2026-79806
- Référence CVE CVE-2026-79807 https://www.cve.org/CVERecord?id=CVE-2026-79807
- Référence CVE CVE-2026-79808 https://www.cve.org/CVERecord?id=CVE-2026-79808
- Référence CVE CVE-2026-79809 https://www.cve.org/CVERecord?id=CVE-2026-79809
- Référence CVE CVE-2026-79810 https://www.cve.org/CVERecord?id=CVE-2026-79810
- Référence CVE CVE-2026-79811 https://www.cve.org/CVERecord?id=CVE-2026-79811
- Référence CVE CVE-2026-79812 https://www.cve.org/CVERecord?id=CVE-2026-79812
- Référence CVE CVE-2026-79813 https://www.cve.org/CVERecord?id=CVE-2026-79813
- Référence CVE CVE-2026-79814 https://www.cve.org/CVERecord?id=CVE-2026-79814
- Référence CVE CVE-2026-79815 https://www.cve.org/CVERecord?id=CVE-2026-79815
- Référence CVE CVE-2026-79816 https://www.cve.org/CVERecord?id=CVE-2026-79816
- Référence CVE CVE-2026-79817 https://www.cve.org/CVERecord?id=CVE-2026-79817
- Référence CVE CVE-2026-79818 https://www.cve.org/CVERecord?id=CVE-2026-79818