← back
CVE-2023-22779criticalCWE-120

Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 2.1%
exploitation probability
2.1%top 20% of all CVEs
observed exploitation
nono source reports it
In short

A buffer overflow vulnerability in Aruba's PAPI protocol allows attackers to send malicious packets to port 8211 without authentication and gain full control of access points by executing arbitrary code. This is critical because it requires no login and affects the core management system.

Technical detail

Unauthenticated buffer overflow in PAPI UDP service (port 8211) permits remote code execution with elevated privileges through specially crafted packets. No authentication is required; successful exploitation grants arbitrary code execution on the underlying OS.

Summary generated and translated by AI from the official description.
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H