CVE-2020-24634
Published on: 12/10/2020 12:00:00 AM UTC
Last Modified on: 11/18/2021 06:17:00 PM UTC
Certain versions of 7005 from Arubanetworks contain the following vulnerability:
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
- CVE-2020-24634 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 10 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Document Display | HPE Support Center | Vendor Advisory support.hpe.com text/html |
![]() |
Related QID Numbers
- 43816 HPE Aruba OS Multiple Security Vulnerabilities (ARUBA-PSA-2020-012)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Arubanetworks | 7005 | - | All | All | All |
Hardware
| Arubanetworks | 7005 | - | All | All | All |
Hardware
| Arubanetworks | 7008 | - | All | All | All |
Hardware
| Arubanetworks | 7008 | - | All | All | All |
Hardware
| Arubanetworks | 7010 | - | All | All | All |
Hardware
| Arubanetworks | 7010 | - | All | All | All |
Hardware
| Arubanetworks | 7024 | - | All | All | All |
Hardware
| Arubanetworks | 7024 | - | All | All | All |
Hardware
| Arubanetworks | 7030 | - | All | All | All |
Hardware
| Arubanetworks | 7030 | - | All | All | All |
Hardware
| Arubanetworks | 7205 | - | All | All | All |
Hardware
| Arubanetworks | 7205 | - | All | All | All |
Hardware
| Arubanetworks | 7210 | - | All | All | All |
Hardware
| Arubanetworks | 7210 | - | All | All | All |
Hardware
| Arubanetworks | 7220 | - | All | All | All |
Hardware
| Arubanetworks | 7220 | - | All | All | All |
Hardware
| Arubanetworks | 7240xm | - | All | All | All |
Hardware
| Arubanetworks | 7240xm | - | All | All | All |
Hardware
| Arubanetworks | 7280 | - | All | All | All |
Hardware
| Arubanetworks | 7280 | - | All | All | All |
Hardware
| Arubanetworks | 9004 | - | All | All | All |
Hardware
| Arubanetworks | 9004 | - | All | All | All |
Hardware
| Arubanetworks | 9004-lte | - | All | All | All |
Hardware
| Arubanetworks | 9004-lte | - | All | All | All |
Hardware
| Arubanetworks | 9012 | - | All | All | All |
Hardware
| Arubanetworks | 9012 | - | All | All | All |
Operating System | Arubanetworks | Arubaos | All | All | All | All |
Operating System | Arubanetworks | Arubaos | All | All | All | All |
Application | Arubanetworks | Sd-wan | All | All | All | All |
Operating System | Arubanetworks | Sd-wan | All | All | All | All |
Operating System | Arubanetworks | Sd-wan | All | All | All | All |
- cpe:2.3:h:arubanetworks:7005:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7005:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7008:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7008:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7010:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7010:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7024:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7024:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7030:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7030:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7205:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7205:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7210:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7210:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7220:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7220:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7240xm:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7240xm:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7280:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:7280:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:9004:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:9004:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:9004-lte:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:9004-lte:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:9012:-:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:9012:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*:
- cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:sd-wan:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:sd-wan:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|