logo

Four Critical Vulnerabilities Expose HPE Aruba Devices to RCE Attacks

ID: 660c11f9-7f19-5b7d-a81d-25bb726d5595

STIX ID: report--660c11f9-7f19-5b7d-a81d-25bb726d5595

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-03

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

HPE Aruba Networking released security updates addressing ten ArubaOS vulnerabilities, four of which are critical unauthenticated buffer overflows (CVSS 9.8) that allow remote code execution via specially crafted packets to the PAPI UDP port 8211; affected Mobility Conductor, Controllers, WLAN and SD‑WAN Gateways across multiple ArubaOS and SD‑WAN versions (including end-of-maintenance releases). Users are advised to apply fixes immediately, with a temporary workaround for ArubaOS 8.x to enable Enhanced PAPI Security using a non-default key; seven issues were credited to researcher “Chancen.”

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.