Wireless Access

last person joined: 16 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

SSLOpen Vunerability/Heartbleed???

This thread has been viewed 0 times
  • 1.  SSLOpen Vunerability/Heartbleed???

    Posted Jun 18, 2014 11:15 AM

    oes the AOS 3.4.5.3 6.1.4.8 6.3.1.8 AWMS 7.7.12 fix the sslopen vunerablities? We have several diffferent models of controllers so that's why we still use 3.4.5.3, and about eight different AWMS appliances.



  • 2.  RE: SSLOpen Vunerability/Heartbleed???
    Best Answer

    EMPLOYEE
    Posted Jun 18, 2014 11:58 AM


  • 3.  RE: SSLOpen Vunerability/Heartbleed???

    Posted Jun 18, 2014 01:32 PM

    Does 6.1.x have an update, I did not see it on the security bulliten?



  • 4.  RE: SSLOpen Vunerability/Heartbleed???

    Posted Jun 22, 2014 11:34 AM

    you talking Heartbleed of the more recent one

     

    heartbleed says

     

    AFFECTED VERSIONS
    -- ArubaOS 6.3.x, 6.4.x

    Previous versions of these products used an earlier version of OpenSSL that is not vulnerable.

     

    the more recent one says

     

    POSSIBLY AFFECTED
        - ArubaOS 5.x, 6.1.x, 6.2.x

    These versions contain an older version of OpenSSL which is not reported to be vulnerable when acting as a TLS server.  Although Aruba does not  believe these versions pose a danger, OpenSSL will be patched during the next scheduled maintenance cycle as a precaution.

     



  • 5.  RE: SSLOpen Vunerability/Heartbleed???

    EMPLOYEE
    Posted Jun 22, 2014 11:37 AM

    @elmodoeswifi wrote:

    Does 6.1.x have an update, I did not see it on the security bulliten?


    "

    POSSIBLY AFFECTED
    	- ArubaOS 5.x, 6.1.x, 6.2.x
    	- ArubaOS 7.x (Mobility Access Switch)
    	  These versions contain an older version of OpenSSL which is not reported
    	  to be vulnerable when acting as a TLS server.  Although Aruba does not
    	  believe these versions pose a danger, OpenSSL will be patched during the
    	  next scheduled maintenance cycle as a precaution.