← back
CVE-2023-45615critical

CVE-2023-45615

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 2.1%
exploitation probability
2.1%top 20% of all CVEs
observed exploitation
nono source reports it
In short

A vulnerability in Aruba access point management allows hackers to send malicious packets over the network and take complete control of the device, running any commands they want without needing a password.

Technical detail

Buffer overflow vulnerabilities in the CLI service accessible via PAPI (UDP port 8211) enable unauthenticated remote code execution. Exploitation requires sending specially crafted packets to the management protocol, resulting in arbitrary code execution with privileged system-level access.

Summary generated and translated by AI from the official description.
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H