PT-2024-2047 · Aruba · Arubaos

Xiaoc

·

Published

2024-03-05

·

Updated

2024-03-06

·

CVE-2024-25615

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ArubaOS versions 8.x
Description The issue is related to insufficient input validation in the Spectrum service of ArubaOS, which can be exploited by a remote attacker to cause a denial-of-service (DoS) using the PAPI protocol. Successful exploitation allows an attacker to interrupt the normal operation of the affected service.
Recommendations For ArubaOS version 8.x, update to a version that includes a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the Spectrum service via the PAPI protocol to minimize the risk of exploitation.

Fix

Resource Exhaustion

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-01925
CVE-2024-25615

Affected Products

Arubaos