Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-26304. PoCs published by X-Projetion.
AI-analyzed exploit summary The repository claims to be a PoC for CVE-2024-26304 (ArubaOS RCE via PAPI UDP port 8211) but contains only a skeletal Python script with placeholder functions and no actual exploit logic. The README describes the vulnerability accurately, but the code lacks implementation details for exploitation.
Description
There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Exploits (1)
The repository claims to be a PoC for CVE-2024-26304 (ArubaOS RCE via PAPI UDP port 8211) but contains only a skeletal Python script with placeholder functions and no actual exploit logic. The README describes the vulnerability accurately, but the code lacks implementation details for exploitation.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H