pwshub.com

HPE patches three critical security holes in Aruba PAPI

Aruba access points running AOS-8 and AOS-10 need to be patched urgently after HPE emitted fixes for three critical flaws in its networking subsidiary's networking access points.

The issues would allow an unauthenticated attacker to run code on Aruba's systems by sending carefully crafted packets to UDP port 8211, the operating system's Proprietary Access Protocol Interface (PAPI), which would provide that miscreant privileged access to the equipment.

The three vulnerabilities - CVE-2024-42505, CVE-2024-42506, and CVE-2024-42507 - are all rated 9.8 out of 10 on the CVSS severity scale.

The flaws affect versions of AOS 10.6.x.x (up to and including 10.6.0.2), as well as Instant AOS 8.12.x.x (8.12.0.1 and earlier versions). HPE is also warning that end-of-life code, including AOS 10.5 and 10.3, and Instant AOS-8.11 - as well as earlier incarnations - and the advice is to upgrade these systems to get protection.

"Enabling cluster-security via the cluster-security command will prevent these vulnerabilities from being exploited in devices running Instant AOS-8.x code," HPE advised in its security alert. "For AOS-10 devices this is not an option and instead access to UDP port 8211 must be blocked from all untrusted networks."

  • Patch up – 4 critical bugs in ArubaOS lead to remote code execution
  • Aruba's AI strategy cuts the backchat, talks network automation instead
  • HPE bakes LLMs into Aruba as AI inches closer to network takeover

It's not the first time PAPI has been shown to have serious problems this year. Back in May, four critical flaws in the system were fixed by Aruba after proof of concept exploit code was released, and then issued more patches less than a week later.

These patches will be of particular concern to sysadmins within the US military. Back in 2020, Aruba scored a major win by becoming the preferred supplier to the Pentagon after the military fell out with Cisco and started replacing its kit.

HPE credited the flaws' discovery to Erik de Jong, a part-time flaw finder whose day job is as a security officer for the Netherlands telco DELTA Fiber. The vulnerabilities were submitted via Bugcrowd, and he has credited his hobby to paying a chunk off his mortgage.

At the time of publication, HPE said that it had seen no evidence that the issues are being exploited in the wild. However, now that patches are out, and given their seriousness, that's likely to change. ®

Source: theregister.com

Related stories
2 weeks ago - No patches yet, remove cups-browsed or block UDP port 631, requires user interaction Final update After days of waiting and anticipation, what was billed as one or more critical unauthenticated remote-code execution vulnerabilities in all...
1 week ago - Logjam 'hurting infosec processes world over' one expert tells us as US body blows its own Sept deadline NIST has made some progress clearing its backlog of security vulnerability reports to process – though it's not quite on target as...
2 weeks ago - 33% of cloud environments using the toolkit impacted, we're told A critical bug in Nvidia's widely used Container Toolkit could allow a rogue user or software to escape their containers and ultimately take complete control of the...
1 month ago - Despite mogul's US acquittal and recent death, IT giant will follow UK fraud case to its 'conclusion' HPE will pursue the widow of Mike Lynch for the $4 billion in damages it sought from him over the Autonomy merger following the Brit...
3 weeks ago - 'These are difficult decisions,' says Antonio Neri Antonio Neri, the former engineer turned chief executive at Hewlett Packard Enterprise, says the company has to pursue its $4 billion claim against former Autonomy boss Mike Lynch's...
Other stories
26 minutes ago - You can still save on Eve smart home products with these remaining Amazon Prime Day discounts.
2 hours ago - You'll get this gift card instantly when you're approved for the Prime Visa card.
2 hours ago - Amazon Prime Day is over, but there are still live deals that can help you save on accessories like these sturdy Torras phone cases.
2 hours ago - If you're looking for reliable internet providers in Douglasville, these are our top picks.
2 hours ago - Give your mattress an added touch of comfort with one of the best mattress pads on this list.