PT-2019-11081 · Aruba · Arubaos

Published

2019-09-04

·

Updated

2019-09-16

·

CVE-2018-7081

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ArubaOS (affected versions not specified)
Description: A remote code execution issue is present in network-listening components. An attacker could exploit this by transmitting specially-crafted IP traffic to a mobility controller, potentially causing a process crash or executing arbitrary code with full system privileges, leading to complete system compromise. The attack requires the ability to transmit traffic to an IP interface on the mobility controller and leverages the PAPI protocol (UDP port 8211). If the mobility controller only bridges L2 traffic and does not have an accessible IP address, it cannot be attacked.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7081

Affected Products

Arubaos