CVE-2023-22787

HIGH

ArubaOS 10.3.0.0-10.3.0.9 and InstantOS 6.4.0.0-6.4.4.7 - Unauthenticated Denial of Service via PAPI Protocol

Title source: llm
STIX 2.1

Description

An unauthenticated Denial of Service (DoS) vulnerability exists in a service accessed via the PAPI protocol provided by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0027
EPSS Percentile 50.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (2)
arubanetworks/arubaos 10.3.0.0 - 10.3.1.0
hp/instantos 6.4.0.0 - 6.4.4.8-4.2.4.20
Published May 08, 2023
Tracked Since Feb 18, 2026