PT-2020-15785 · Aruba Networks · Aruba 7000 Series Mobility Controllers+2

Published

2020-12-11

·

Updated

2021-11-18

·

CVE-2020-24634

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Aruba 9000 Gateway versions 2.1.0.1 through 2.2.0.0 Aruba 7000 Series Mobility Controllers versions 6.4.4.23 through 6.5.4.17 Aruba 7200 Series Mobility Controllers versions 8.2.2.9 through 8.7.0.0
Description An attacker can remotely inject arbitrary commands by sending specially crafted packets to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access points or controllers.
Recommendations For Aruba 9000 Gateway versions 2.1.0.1 through 2.2.0.0, update to a version above 2.2.0.0. For Aruba 7000 Series Mobility Controllers versions 6.4.4.23 through 6.5.4.17, update to a version above 6.5.4.17. For Aruba 7200 Series Mobility Controllers versions 8.2.2.9 through 8.7.0.0, update to a version above 8.7.0.0. As a temporary workaround, consider restricting access to the PAPI UDP port (8211) until a patch is available.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24634

Affected Products

Aruba 7000 Series Mobility Controllers
Aruba 7200 Series Mobility Controllers
Aruba 9000 Gateway