« Volver al listado

CVE-2024-33516

Estado: AnalizadaAlta (7.5)—

An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-33516",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-33516",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-02T15:59:36.938795Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-alert@hpe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "Hewlett Packard Enterprise (HPE)",
          "product": "Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central",
          "versions": [
            {
              "status": "affected",
              "version": "ArubaOS 10.5.x.x: 10.5.1.0 and below"
            },
            {
              "status": "affected",
              "version": "ArubaOS 10.4.x.x: 10.4.1.0 and below"
            },
            {
              "status": "affected",
              "version": "ArubaOS 8.11.x.x: 8.11.2.1 and below"
            },
            {
              "status": "affected",
              "version": "ArubaOS 8.10.x.x: 8.10.0.10 and below"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:8.10.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "8.10.0.0",
              "lessThan": "8.10.0.10",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:10.5.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "10.5.0.0",
              "lessThan": "10.5.1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:10.4.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "10.4.0.0",
              "lessThan": "10.4.1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:8.11.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "8.11.0.0",
              "lessThan": "8.11.2.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:10.3.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "10.3.0.0",
              "lessThan": "10.4.0.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:8.9.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "8.9.0.0",
              "lessThan": "8.10.0.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:8.8.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "8.8.0.0",
              "lessThan": "8.9.0.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:8.7.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "8.7.0.0",
              "lessThan": "8.8.0.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:8.6.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "8.6.0.0",
              "lessThan": "8.7.0.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:6.5.4.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "6.5.4.0",
              "lessThan": "6.5.5.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:arubanetworks:sd-wan:8.7.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "sd-wan",
          "versions": [
            {
              "status": "affected",
              "version": "8.7.0.0",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:arubanetworks:sd-wan:8.6.0.4:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "sd-wan",
          "versions": [
            {
              "status": "affected",
              "version": "8.6.0.4",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-05-01T17:15:37.000",
  "references": [
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-004.txt",
      "tags": [
        "Broken Link"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-004.txt",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided  by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.\n\n"
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de denegación de servicio (DoS) no autenticada en el servicio de autenticación al que se accede a través del protocolo PAPI proporcionado por ArubaOS. La explotación exitosa de esta vulnerabilidad da como resultado la capacidad de interrumpir el funcionamiento normal del controlador."
    }
  ],
  "lastModified": "2026-06-17T07:31:54.413",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "687598A9-2EB1-4E01-BC09-29C8D958FF84",
              "versionEndIncluding": "8.10.0.10",
              "versionStartIncluding": "8.10.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23F5B363-53C1-4F6C-96FB-1D2040AB3799",
              "versionEndIncluding": "8.11.2.1",
              "versionStartIncluding": "8.11.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5E2EB73-BD2F-4777-8892-A815287C67F8",
              "versionEndIncluding": "10.4.1.0",
              "versionStartIncluding": "10.4.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8DB89D7-E1FA-4CF1-AB2E-F6A095988D76",
              "versionEndIncluding": "10.5.1.0",
              "versionStartIncluding": "10.5.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}