CVE-2024-33516: High severity hpe arubaos vulnerability
Published May 1, 2024
·Updated
An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.
Affected Software
5 affected components
Aruba ArubaOS
Arubanetworks Arubaos>=8.10.0.0<=8.10.0.10
Arubanetworks Arubaos>=8.11.0.0<=8.11.2.1
Arubanetworks Arubaos>=10.4.0.0<=10.4.1.0
Arubanetworks Arubaos>=10.5.0.0<=10.5.1.0
Event History
May 1, 2024
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
May 2, 2024
News Published
via The Register·08:30 PM
News Published
via The Register·08:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-33516?
The severity of CVE-2024-33516 is critical, as it allows for unauthenticated Denial of Service attacks.
2
How do I fix CVE-2024-33516?
To fix CVE-2024-33516, apply the latest security patches provided by Aruba for ArubaOS.
3
What systems are affected by CVE-2024-33516?
CVE-2024-33516 affects systems running ArubaOS that utilize the PAPI protocol.
4
What are the potential impacts of CVE-2024-33516?
The potential impacts of CVE-2024-33516 include interruption of normal operations of the affected controllers.
5
Is CVE-2024-33516 exploitable remotely?
Yes, CVE-2024-33516 can be exploited remotely due to its unauthenticated nature.