Security

 View Only
last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

status products affected by log4j (CVE-2021-44228) vulnerability?

This thread has been viewed 206 times
  • 1.  status products affected by log4j (CVE-2021-44228) vulnerability?

    Posted Dec 13, 2021 01:49 AM
    perhaps im not looking where i should but im not finding any information on which products are and aren't affected by the log4j vulnerability. 

    has anyone heard something or have a link to share?


  • 2.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    EMPLOYEE
    Posted Dec 13, 2021 03:29 AM
    Aruba normally issues security advisories for vulnerabilities that are present, but not for those that do not affect Aruba products.

    If you need an authoritative answer, please contact TAC, but I have seen answers in the line that after investigations by the internal security and product teams there are no indications that the log4j vulnerability affects any Aruba product.

    I'll try to update this post if at some point official communication appears, but for now, reaching out to TAC is the way to get an official statement.

    Just got the official statement for the Aruba SIRT:

    After investigating with the product teams and performing different tests in the Aruba products, Aruba SIRT has determined that no Aruba product is vulnerable to CVE-2021-44228.

     

    Should anything change, a Security Advisory will be published on https://www.arubanetworks.com/support-services/security-bulletins


    UPDATE: Bulletin posted: https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-019.txt

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    Posted Dec 13, 2021 04:12 AM
    thank you Herman.

    the TAC case is open and i do understand the position of not releasing security advisories for issues that don't affect the products.

    personally i feel that in the case of vulnerabilities with this amount of attention a simple statement we are not affected probably saves a lot uncertainty and TAC cases. your reply already helped in that for me.


  • 4.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    Posted Dec 13, 2021 06:04 AM
    I have the same answer from TAC:

    From case description, I could see that you have a query regarding log4j vulnerability.

    After investigating with the product teams and performing different tests on the Aruba products, Aruba SIRT has determined that no Aruba Product is vulnerable to CVE-2021-44228.

     



    ------------------------------
    Thomas
    ------------------------------



  • 5.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    Posted Dec 13, 2021 06:14 AM
    Apparently SilverPeak is affected => https://www.arubanetworks.com/website/techdocs/sdwan/docs/advisories/media/security_advisory_notice_apache_log4j2_cve_2021_44228.pdf
    but does TAC see it as an Aruba Product yet ?

    ------------------------------
    Thomas
    ------------------------------



  • 6.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    MVP EXPERT
    Posted Dec 13, 2021 06:06 AM
    flowing this post, please share if you have some info from tac

    ------------------------------
    Marcel Koedijk | MVP Guru 2021 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opionions are my own
    ------------------------------



  • 7.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    Posted Dec 13, 2021 06:11 AM
    I got the same reply as Thomas, no products affected.


  • 8.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    Posted Dec 13, 2021 06:22 AM
    Aruba Instant On uses a vulnerable version of log4j:
    https://www.arubainstanton.com/eula/

    ------------------------------
    Erwin Commandeur
    ------------------------------



  • 9.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    Posted Dec 13, 2021 02:26 PM
    Any update from Aruba on this yet?

    ------------------------------
    Garrett Masters
    ------------------------------



  • 10.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    EMPLOYEE
    Posted Dec 13, 2021 06:09 PM
    https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-019.txt

    ------------------------------
    Gowri Sankar Amujuri
    ------------------------------



  • 11.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    Posted Dec 15, 2021 02:04 AM
    Hello,

    according to this HPE Security Bulletin the IMC is also affected:
    https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04215en_us


    ------------------------------
    joachim wellinghof
    ------------------------------



  • 12.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    MVP GURU
    Posted Dec 15, 2021 03:27 AM
    Here instead the HPE Support Alert - Customer Notice (Apache Software Log4j - Security Vulnerability CVE-2021-44228) with the current list of HPE/Aruba products declared as not affected by CVE-2021-44228.

    Reference here.

    ------------------------------
    Davide Poletto
    ------------------------------



  • 13.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    EMPLOYEE
    Posted Dec 15, 2021 09:13 AM
    Hello,

    what about H3C/Comware switches ? I don't see them in either affected or unaffected products' lists. Or perhaps they are listed with an "Aruba" name I'm not aware of ?
    (I used to support ProCurve/PVOS and H3C)

    By the way, what are"ArubaOS-S" switches  exactly ?

    Thanks.

    ------------------------------
    Nicolas Hatton
    ------------------------------



  • 14.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    MVP EXPERT
    Posted Dec 15, 2021 10:14 AM
    Confirmed by TAC Support that Comware/H3C is not affected.

    ------------------------------
    Marcel Koedijk | MVP Guru 2021 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opionions are my own
    ------------------------------



  • 15.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    Posted Dec 16, 2021 12:10 AM
    I cannot swear to this, but I believe the ArubaOS-S switches are the HP ProCurve switches that were rebranded as HPE Aruba switches.

    ------------------------------
    Phillip Barton
    ------------------------------



  • 16.  RE: status products affected by log4j (CVE-2021-44228) vulnerability?

    EMPLOYEE
    Posted Dec 16, 2021 06:17 AM
    Hi Philip,
    yes, I agree. We can see this name on the firmware download page : AOS-S for the "ProCurve" stuff while the Aruba shiny is "ArubaOS-CX".

    What confused me is that in that list we also see "PVOS", which I guess is the same.

    And thanks Marcel. The "not affected" page has been updated with this info at last ;-)

    Cheers.

    ------------------------------
    Nicolas Hatton
    ------------------------------