CVE-2009-3836: Medium severity arubaos vulnerability
Published Nov 2, 2009
·Updated
ArubaOS 3.3.1.x, 3.3.2.x, RN 3.1.x, 3.4.x, and 3.3.2.x-FIPS on the Aruba Mobility Controller allows remote attackers to cause a denial of service (Access Point crash) via a malformed 802.11 Association Request management frame.
Affected Software
8 affected components
Arubanetworks Arubaos=3.1.1-rn
Arubanetworks Arubaos=3.3.1.16
Arubanetworks Arubaos=3.3.1.29
Arubanetworks Arubaos=3.3.1.30
Arubanetworks Arubaos=3.3.2.6
Arubanetworks Arubaos=3.3.2.14-fips
Arubanetworks Arubaos=3.4.0
Arubanetworks Aruba Mobility Controller
Event History
Nov 2, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
03:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-3836?
CVE-2009-3836 has a severity level that allows remote attackers to cause a denial of service, impacting the stability of Access Points.
2
How do I fix CVE-2009-3836?
To fix CVE-2009-3836, ensure you update the ArubaOS to the latest version that addresses this vulnerability.
3
What versions of ArubaOS are affected by CVE-2009-3836?
CVE-2009-3836 affects ArubaOS versions 3.3.1.x, 3.3.2.x, RN 3.1.x, and 3.4.x.
4
What type of attack does CVE-2009-3836 facilitate?
CVE-2009-3836 facilitates a denial of service attack that can crash Access Points.
5
Is there a workaround for CVE-2009-3836?
There are no documented workarounds for CVE-2009-3836, so updating the software is recommended.