CVE-2024-31470
CRITICALArubaOS 10.3.0.0-10.4.1.0 and InstantOS 6.4.0.0-8.6.0.23 - Unauthenticated Remote Code Execution via SAE Packet Handling
Title source: llmDescription
There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
References (2)
Core 2
Core References
Vendor Advisory
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04647en_us&docLocale=en_US
Broken Link, Vendor Advisory
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt
Scores
CVSS v3
9.8
EPSS
0.0402
EPSS Percentile
88.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-121
Status
published
Products (2)
arubanetworks/arubaos
10.3.0.0 - 10.4.1.1
hp/instantos
6.4.0.0 - 8.6.0.24
Published
May 14, 2024
Tracked Since
Feb 18, 2026