CVE-2020-24633: Buffer Overflow
There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24633?
CVE-2020-24633 is a vulnerability that allows unauthenticated remote code execution by sending specially crafted packets to the PAPI UDP port of Aruba Networks access points or controllers.
Which software versions are affected by CVE-2020-24633?
ArubaOS versions between 6.4.4.24 and 8.7.1.0 are affected by CVE-2020-24633.
How severe is CVE-2020-24633?
CVE-2020-24633 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
How can CVE-2020-24633 be fixed?
To fix CVE-2020-24633, it is recommended to update ArubaOS to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2020-24633?
More information about CVE-2020-24633 can be found at the following link: [link](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04072en_us).