CVE-2021-37720: Arubanetworks Arubaos
High severity, CVSS 7.2. EPSS: 3.1% chance of exploitation in the next 30 days.
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Affected products
- Arubanetworks Arubaos: from 6.4.4.0, before 6.4.4.25 (fixed in 6.4.4.25); from 6.5.4.0, before 6.5.4.20 (fixed in 6.5.4.20); from 8.3.0.0, before 8.3.0.16 (fixed in 8.3.0.16); from 8.5.0.0, before 8.5.0.13 (fixed in 8.5.0.13); from 8.6.0.0, before 8.6.0.9 (fixed in 8.6.0.9); from 8.7.0.0, before 8.7.1.4 (fixed in 8.7.1.4)
- Arubanetworks SD-WAN: from 2.2.0.0, before 2.2.0.4 (fixed in 2.2.0.4)
- Siemens Scalance w1750d Firmware: affected versions not specified
Published 2021-09-07. Last modified 2026-06-17.