Aruba Security Updates – 15 May 2024

Aruba has released security updates to fix multiple vulnerabilities affecting ArubaOS and InstantOS.

The addressed vulnerabilities could allow the attacker to obtain sensitive information, perform denial of service attacks, manipulate data, or execute arbitrary code and gain access to the affected product.

Sample of the addressed vulnerabilities:

1. Aruba Instantos/Arubaos PAPI Buffer Overflow Vulnerability (CVE-2024- 31466):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. Aruba InstantOS/ArubaOS Soft AP Daemon Denial of Service Vulnerability (CVE-2024-31478):

  • CVSS: 5.3
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

Affected Products:

  • ArubaOS 10.5.x.x:10.5.1.0 and below.
  • ArubaOS 10.4.x.x:10.4.1.0 and below.
  • InstantOS 8.11.x.x:8.11.2.1 and below.
  • InstantOS 8.10.x.x:8.10.0.10 and below.
  • InstantOS 8.6.x.x:8.6.0.23 and below.
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Aruba Security Advisory

References