« Volver al listado

CVE-2020-24633

Estado: ModificadaCrítica (9.8)—

There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-24633",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Aruba 9000 Gateway",
          "versions": [
            {
              "status": "affected",
              "version": "2.1.0.1"
            },
            {
              "status": "affected",
              "version": "2.2.0.0 and below"
            }
          ]
        },
        {
          "vendor": "n/a",
          "product": "Aruba 7000 Series Mobility Controllers",
          "versions": [
            {
              "status": "affected",
              "version": "6.4.4.23"
            },
            {
              "status": "affected",
              "version": "6.5.4.17"
            },
            {
              "status": "affected",
              "version": "8.2.2.9"
            },
            {
              "status": "affected",
              "version": "8.3.0.13"
            },
            {
              "status": "affected",
              "version": "8.5.0.10"
            },
            {
              "status": "affected",
              "version": "8.6.0.5"
            },
            {
              "status": "affected",
              "version": "8.7.0.0 and below"
            }
          ]
        },
        {
          "vendor": "n/a",
          "product": "Aruba 7200 Series Mobility Controllers",
          "versions": [
            {
              "status": "affected",
              "version": "6.4.4.23"
            },
            {
              "status": "affected",
              "version": "6.5.4.17"
            },
            {
              "status": "affected",
              "version": "8.2.2.9"
            },
            {
              "status": "affected",
              "version": "8.3.0.13"
            },
            {
              "status": "affected",
              "version": "8.5.0.10"
            },
            {
              "status": "affected",
              "version": "8.6.0.5"
            },
            {
              "status": "affected",
              "version": "8.7.0.0 and below"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-11T02:15:10.943",
  "references": [
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04072en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04072en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below."
    },
    {
      "lang": "es",
      "value": "Se presentan múltiples vulnerabilidades de desbordamiento de búfer que podrían conllevar a una ejecución de código remota no autenticada mediante el envío de paquetes especialmente diseñados destinados al puerto UDP (8211) de PAPI (protocolo de administración Aruba Networks AP) de puntos de acceso o controladores en Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers versiones: 2.1.0.1, 2.2.0.0 y por debajo; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 y por debajo; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 y por debajo"
    }
  ],
  "lastModified": "2026-06-17T03:05:53.677",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE1BBC46-36EA-47DE-9173-707A23325F1A",
              "versionEndExcluding": "6.4.4.24"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66C41F7C-BB41-449A-B030-C029E33AD041",
              "versionEndExcluding": "6.5.4.18",
              "versionStartIncluding": "6.5.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65383999-0515-4646-9510-677D33ECBB11",
              "versionEndExcluding": "8.2.2.10",
              "versionStartIncluding": "8.0.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3E3ED71-0BA0-4D76-9BB7-D84FA571C4D0",
              "versionEndExcluding": "8.3.0.14",
              "versionStartIncluding": "8.3.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "419BC61F-B002-4848-BB6B-51CA15C8E6F2",
              "versionEndExcluding": "8.5.0.11",
              "versionStartIncluding": "8.4.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6A4597E-0267-4DA8-BFFB-513BEA7D04D4",
              "versionEndExcluding": "8.6.0.6",
              "versionStartIncluding": "8.6.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "894088FF-5838-4CE7-AA31-CE7FB247E271",
              "versionEndExcluding": "8.7.1.0",
              "versionStartIncluding": "8.7.0.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arubanetworks:7005:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FE128072-9444-40D5-AC86-BB317869EB97"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:7008:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F747F71E-66BC-4776-BCCC-3123F8EEEBC6"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:7010:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "59612211-5054-44DC-B028-61A2C5C6133D"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:7024:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "15FE873C-3C45-4EA3-9AD1-D07F132BC31F"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:7030:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E8E68DB6-149B-4469-BD27-69F1AC59166F"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:7205:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2E9AA178-1327-402E-8740-8409ECA448BC"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:7210:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9969F899-4D7A-4DD5-B81D-DB16B20CF86A"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:7220:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CF33BAD0-0596-4910-B096-99E2033F73D8"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:7240xm:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FDDFDA5E-3895-463A-86EA-1823EC1B5045"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:7280:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3BBA9A71-BE10-471A-A8BE-5CCB8CE8393F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A206DE28-E15A-437B-BC1C-261F32F24F3A",
              "versionEndExcluding": "2.1.0.2"
            },
            {
              "criteria": "cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1D1957E-1DFE-495B-8DF5-C1640857DDF4",
              "versionEndExcluding": "2.2.0.1",
              "versionStartIncluding": "2.2.0.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arubanetworks:9004:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CFA13FF5-7C60-48B4-AF46-18A9F19D5D42"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:9004-lte:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0B1EB3D9-77B5-4DBE-9518-23DD0DA06BC9"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:9012:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "17162DB3-973E-47C6-9157-39A0E94603F2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}