There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos 10 | — | Please note that due to the structure of these specific vulnerabilities Aruba was able to patch them only in the following branches: - ArubaOS 10.4.x: 10.4.0.0 and above - Aruba InstantOS 8.11.x: 8.11.0.0 and above - Aruba InstantOS 8.10.x: 8.10.0.3 and above Older branches and branches not specifically named are not patched. Customers unable to upgrade should consult the workaround section | Jan 14, 2025 | May 9, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub