logo

HPE patches three critical security holes in Aruba PAPI

ID: 67f098e7-393d-5792-805a-7a97ab5c1bd0

STIX ID: report--67f098e7-393d-5792-805a-7a97ab5c1bd0

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-09-26

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Aruba access points running AOS-8 and AOS-10 require urgent patching after HPE released fixes for three critical (CVSS 9.8) vulnerabilities that allow unauthenticated remote code execution via UDP port 8211 (PAPI); affected versions include AOS 10.6.x and Instant AOS 8.12.x (and earlier/end-of-life releases). HPE recommends enabling cluster-security on Instant AOS-8.x or blocking UDP 8211 from untrusted networks for AOS-10, and notes no evidence of in-the-wild exploitation at the time of publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.