PT-2024-2048 · Aruba · Arubaos

Aruba Engineering

·

Published

2024-03-05

·

Updated

2024-03-06

·

CVE-2024-25616

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ArubaOS (affected versions not specified)
Description The issue is related to certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex and depend on factors beyond the control of attackers. The vulnerability is associated with shortcomings in the authentication procedure, which can allow a remote attacker to gain unauthorized access to protected information during the IKE AUTH negotiation process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-01926
CVE-2024-25616

Affected Products

Arubaos