logo

Patch up – 4 critical bugs in ArubaOS lead to remote code execution

ID: a333f735-8bdc-5986-ada9-4daa8b821952

STIX ID: report--a333f735-8bdc-5986-ada9-4daa8b821952

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-05-02

Date Updated: 2026-04-26

Author: Connor Jones

...
...

HPE Aruba disclosed ten vulnerabilities in ArubaOS, including four critical 9.8-rated buffer overflows that could allow remote code execution via the PAPI UDP port (8211) on Mobility Conductors, Controllers, WLAN gateways and SD‑WAN gateways; six additional medium-severity DoS/buffer overflow flaws were also reported. A temporary mitigation is to enable PAPI Security with a non-default key, but administrators are urged to upgrade affected ArubaOS/SD‑WAN versions per the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.