« Back to list

CVE-2024-25616

Status: AnalyzedLow (3.7)—

Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-25616",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-25616",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-06T15:07:21.258099Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-alert@hpe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "Hewlett Packard Enterprise (HPE)",
          "product": "ArubaOS Wi-Fi Controllers and Campus/Remote Access Points",
          "versions": [
            {
              "status": "affected",
              "version": "ArubaOS 10.5.x.x: 10.5.0.1 and below"
            },
            {
              "status": "affected",
              "version": "ArubaOS 10.4.x.x: 10.4.0.3 and below"
            },
            {
              "status": "affected",
              "version": "ArubaOS 8.11.x.x: 8.11.2.0 and below"
            },
            {
              "status": "affected",
              "version": "ArubaOS 8.10.x.x:  8.10.0.9 and below"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-03-05T21:15:08.807",
  "references": [
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-002.txt",
      "tags": [
        "Broken Link"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-002.txt",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.\n\n"
    },
    {
      "lang": "es",
      "value": "Aruba ha identificado ciertas configuraciones de ArubaOS que pueden conducir a la divulgación parcial de información confidencial en el proceso de negociación IKE_AUTH. Los escenarios en los que puede ocurrir la divulgación de información potencialmente confidencial son complejos y dependen de factores que escapan al control de los atacantes."
    }
  ],
  "lastModified": "2026-06-17T07:16:18.097",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2697A3FE-2435-49E4-9E21-AB4F7D664D62",
              "versionEndExcluding": "8.10.0.10",
              "versionStartIncluding": "8.10.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5CAF4A34-8D72-4337-A761-FDB404816DBE",
              "versionEndExcluding": "8.11.2.1",
              "versionStartIncluding": "8.11.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "461A0E90-278E-4759-94C7-F18510AA9C13",
              "versionEndExcluding": "10.4.1.0",
              "versionStartIncluding": "10.4.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42E8AC1B-B80A-43C4-B4CE-C9CDF23E7DD3",
              "versionEndExcluding": "10.5.1.0",
              "versionStartIncluding": "10.5.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}