PT-2019-11081 · Aruba · Arubaos
Published
2019-09-04
·
Updated
2019-09-16
·
CVE-2018-7081
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ArubaOS (affected versions not specified)
Description:
A remote code execution issue is present in network-listening components. An attacker could exploit this by transmitting specially-crafted IP traffic to a mobility controller, potentially causing a process crash or executing arbitrary code with full system privileges, leading to complete system compromise. The attack requires the ability to transmit traffic to an IP interface on the mobility controller and leverages the PAPI protocol (UDP port 8211). If the mobility controller only bridges L2 traffic and does not have an accessible IP address, it cannot be attacked.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arubaos