peter bassill · operator
$ cve CVE-2020-24633 JSON

CVE-2020-24633

9.8
CRITICAL · CVSS 3.1 · EPSS 5.1% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.11% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2020-12-11
Last modified2026-06-17

Affected (15)

VendorProduct
arubanetworks7005
arubanetworks7008
arubanetworks7010
arubanetworks7024
arubanetworks7030
arubanetworks7205
arubanetworks7210
arubanetworks7220
arubanetworks7240xm
arubanetworks7280
arubanetworks9004
arubanetworks9004-lte
arubanetworks9012
arubanetworksarubaos
arubanetworkssd-wan

References

→ the Explorer  ·  watch your stack  ·  NVD