CVE-2024-25615: Medium severity hpe arubaos vulnerability
Published Mar 5, 2024
·Updated
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
Affected Software
5 affected components
Aruba ArubaOS>=8.0
Arubanetworks Arubaos>=8.10.0.0<8.10.0.10
Arubanetworks Arubaos>=8.11.0.0<8.11.2.1
Arubanetworks Arubaos>=10.4.0.0<10.4.1.0
Arubanetworks Arubaos>=10.5.0.0<10.5.1.0
Event History
Mar 5, 2024
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionSeverity
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25615?
CVE-2024-25615 is classified as a critical Denial-of-Service vulnerability.
2
How do I fix CVE-2024-25615?
To remediate CVE-2024-25615, upgrade to the latest version of ArubaOS that addresses this vulnerability.
3
What kind of attack does CVE-2024-25615 enable?
CVE-2024-25615 allows attackers to execute a Denial-of-Service attack against the Spectrum service.
4
Which versions of ArubaOS are affected by CVE-2024-25615?
ArubaOS versions 8.0 and above are vulnerable to CVE-2024-25615.
5
Is authentication required to exploit CVE-2024-25615?
No, CVE-2024-25615 can be exploited without authentication.