Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
CVE-2023-22781
What is CVE-2023-22781?
A critical buffer overflow vulnerability exists within Aruba Networking's Access Point Management Protocol, specifically affecting multiple underlying services. An attacker can exploit this vulnerability by sending specially crafted packets to the PAPI UDP port (8211), potentially leading to unauthorized remote code execution. If successfully exploited, this can grant the attacker the ability to execute arbitrary code with elevated privileges on the affected system, posing a significant risk to network security and integrity.
Affected Version(s)
Aruba Access Points running InstantOS and ArubaOS 10 InstantOS 8.10.x.x: 8.10.0.2 and below
Aruba Access Points running InstantOS and ArubaOS 10 InstantOS 8.10.x.x: 8.10.0.2 and below
Aruba Access Points running InstantOS and ArubaOS 10 ArubaOS 10.3.x.x: 10.3.1.4 and below