Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 2.1%
exploitation probability
2.1%top 20% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in Aruba's access point management protocol (PAPI) allows attackers to send specially crafted packets to crash services or execute malicious code without needing a password. This is critical because it gives attackers full control over network equipment.
Technical detail
Buffer overflow vulnerabilities exist in services accessible via PAPI (UDP port 8211) without authentication, enabling remote code execution with elevated privileges. Exploitation requires sending malformed packets to trigger memory corruption; successful attacks result in arbitrary code execution on the underlying OS.
Summary generated and translated by AI from the official description.
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H