Vulnerability Intelligence Report
CVE-2020-24634
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:2.05%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| arubanetworks | arubaos | all |
| arubanetworks | 7005 | all |
| arubanetworks | 7008 | all |
| arubanetworks | 7010 | all |
| arubanetworks | 7024 | all |
| arubanetworks | 7030 | all |
| arubanetworks | 7205 | all |
| arubanetworks | 7210 | all |
| arubanetworks | 7220 | all |
| arubanetworks | 7240xm | all |
| arubanetworks | 7280 | all |
| arubanetworks | sd-wan | all |
| arubanetworks | 9004 | all |
| arubanetworks | 9004-lte | all |
| arubanetworks | 9012 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
2.051%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Hewlett Packard Enterprise (HPE) · Vendor · USA |
| Reserved | 2020-08-25T00:00:00 |
| Published | 2020-12-11T01:22:50 |
| Last Updated | 2024-08-04T15:19:09 |
Community Chatter & Buzz