Aruba Mobility Controller LDAP Authentication Bypass Vulnerability
BID:27144
Info
Aruba Mobility Controller LDAP Authentication Bypass Vulnerability
| Bugtraq ID: | 27144 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0150 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Arubanetworks Aruba Mobility Controllers 3.1.1.3 Arubanetworks Aruba Mobility Controllers 2.5.5.7 Arubanetworks Aruba Mobility Controllers 2.5.4.25 Arubanetworks Aruba Mobility Controllers 2.5.2.11 Arubanetworks Aruba Mobility Controllers 2.4.8.11-FIPS Arubanetworks Aruba Mobility Controllers 2.3.6.15 |
| Not Vulnerable: | |
Discussion
Aruba Mobility Controller LDAP Authentication Bypass Vulnerability
Aruba Mobility Controller is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected device. This may lead to other attacks.
This issue affects Aruba Mobility Controller firmware 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, 2.4.8.11-FIPS, and prior versions using LDAP authentication for management and VPN user-authentication.
Aruba Mobility Controller is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected device. This may lead to other attacks.
This issue affects Aruba Mobility Controller firmware 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, 2.4.8.11-FIPS, and prior versions using LDAP authentication for management and VPN user-authentication.
Exploit / POC
Aruba Mobility Controller LDAP Authentication Bypass Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Aruba Mobility Controller LDAP Authentication Bypass Vulnerability
Solution:
The vendor released patches to address this issue. Please contact the vendor for information on how to obtain and apply these patches.
Solution:
The vendor released patches to address this issue. Please contact the vendor for information on how to obtain and apply these patches.
References
Aruba Mobility Controller LDAP Authentication Bypass Vulnerability
References:
References:
- Aruba Mobility Controller Homepage (Aruba Networks)
- Aruba Mobility Controller User Authentication Vulnerability (Aruba Networks)