Aruba Networks InstantOS是美国安移通(Aruba Networks)公司的一个基于 Arch Linux 的发行版。 Aruba InstantOS和ArubaOS 10存在安全漏洞,该漏洞源于在PAPI协议访问的服务中存在未经身份验证的拒绝服务(DoS)漏洞,攻击者利用此漏洞可以中断受影响接入点的正常运行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | Aruba Access Points running InstantOS and ArubaOS 10 | Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-22786 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol |
| CVE-2023-22785 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol |
| CVE-2023-22784 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol |
| CVE-2023-22783 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol |
| CVE-2023-22782 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol |
| CVE-2023-22781 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol |
| CVE-2023-22780 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol |
| CVE-2023-22779 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol |
| CVE-2023-22790 | 7.2 HIGH | Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Inter |
| CVE-2023-22789 | 7.2 HIGH | Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Inter |
| CVE-2023-22788 | 7.2 HIGH | Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Inter |
| CVE-2023-22791 | 5.4 MEDIUM | Aruba InstantOS and ArubaOS 10 Sensitive Information Disclosure |
No comments yet