PT-2020-15784 · Aruba Networks · Aruba 7000 Series Mobility Controllers+2

Published

2020-12-11

·

Updated

2021-11-18

·

CVE-2020-24633

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Aruba 9000 Gateway versions prior to the fixed version Aruba 7000 Series Mobility Controllers versions prior to the fixed version Aruba 7200 Series Mobility Controllers versions 2.1.0.1 through 2.2.0.0 Aruba 7200 Series Mobility Controllers versions 6.4.4.23 through 8.7.0.0
Description There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers.
Recommendations For Aruba 9000 Gateway, update to a version that includes the fix for this issue. For Aruba 7000 Series Mobility Controllers, update to a version that includes the fix for this issue. For Aruba 7200 Series Mobility Controllers version 2.1.0.1 through 2.2.0.0, update to a version that includes the fix for this issue. For Aruba 7200 Series Mobility Controllers version 6.4.4.23 through 8.7.0.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the PAPI UDP port (8211) to minimize the risk of exploitation.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24633

Affected Products

Aruba 7000 Series Mobility Controllers
Aruba 7200 Series Mobility Controllers
Aruba 9000 Gateway