CVE-2024-31470: Buffer Overflow
Published May 14, 2024
·Updated
There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Affected Software
4 affected components
Arubanetworks Arubaos>=10.3.0.0<10.4.1.1
Arubanetworks Arubaos>=10.5.0.0<10.5.1.1
HP Instantos>=6.4.0.0<8.6.0.24
HP Instantos>=8.7.0.0<8.10.0.11
Event History
May 14, 2024
CVE Published
via MITRE·10:26 PM
Data Sourced
via MITRE·10:26 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software