PT-2020-15784 · Aruba Networks · Aruba 7000 Series Mobility Controllers+2
Published
2020-12-11
·
Updated
2021-11-18
·
CVE-2020-24633
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Aruba 9000 Gateway versions prior to the fixed version
Aruba 7000 Series Mobility Controllers versions prior to the fixed version
Aruba 7200 Series Mobility Controllers versions 2.1.0.1 through 2.2.0.0
Aruba 7200 Series Mobility Controllers versions 6.4.4.23 through 8.7.0.0
Description
There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers.
Recommendations
For Aruba 9000 Gateway, update to a version that includes the fix for this issue.
For Aruba 7000 Series Mobility Controllers, update to a version that includes the fix for this issue.
For Aruba 7200 Series Mobility Controllers version 2.1.0.1 through 2.2.0.0, update to a version that includes the fix for this issue.
For Aruba 7200 Series Mobility Controllers version 6.4.4.23 through 8.7.0.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the PAPI UDP port (8211) to minimize the risk of exploitation.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aruba 7000 Series Mobility Controllers
Aruba 7200 Series Mobility Controllers
Aruba 9000 Gateway