A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could allow a remote malicious actor to perform unauthorized frame injection, bypass client isolation, interfere with cross-client traffic, and compromise network segmentation, integrity, and confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos 10 | — | Upgrade Mobility Conductors, Controllers, Gateways, and Access Points to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section:
- AOS-10.8.x.x: 10.8.0.1 and above
- AOS-10.7.x.x: 10.7.2.3 and above
- AOS-10.4.x.x: 10.4.1.11 and above
- AOS-8.13.x.x: 8.13.1.2 and above
- AOS-8.12.x.x: 8.12.0.7 and above
- AOS-8.10.x.x: 8.10.0.22 and above
NOTE: After upgrading AOS software, the "group-frame-block" setting must also be enabled to fully mitigate the vulnerabilities.
Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/globalsearch#tab=Software
HPE Aruba Networking does not evaluate or patch AOS-10 and AOS-8 software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw. | Mar 16, 2026 | Mar 3, 2026 |
| Aruba Aos 8 | — | Upgrade Mobility Conductors, Controllers, Gateways, and Access Points to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section:
- AOS-10.8.x.x: 10.8.0.1 and above
- AOS-10.7.x.x: 10.7.2.3 and above
- AOS-10.4.x.x: 10.4.1.11 and above
- AOS-8.13.x.x: 8.13.1.2 and above
- AOS-8.12.x.x: 8.12.0.7 and above
- AOS-8.10.x.x: 8.10.0.22 and above
NOTE: After upgrading AOS software, the "group-frame-block" setting must also be enabled to fully mitigate the vulnerabilities.
Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/globalsearch#tab=Software
HPE Aruba Networking does not evaluate or patch AOS-10 and AOS-8 software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw. | Mar 16, 2026 | Mar 3, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub