PT-2019-11081 · Aruba · Arubaos

Publicado

2019-09-04

·

Atualizado

2019-09-16

·

CVE-2018-7081

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ArubaOS (affected versions not specified)
Description: A remote code execution issue is present in network-listening components. An attacker could exploit this by transmitting specially-crafted IP traffic to a mobility controller, potentially causing a process crash or executing arbitrary code with full system privileges, leading to complete system compromise. The attack requires the ability to transmit traffic to an IP interface on the mobility controller and leverages the PAPI protocol (UDP port 8211). If the mobility controller only bridges L2 traffic and does not have an accessible IP address, it cannot be attacked.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7081

Produtos afetados

Arubaos