9.8

CVE-2022-37888

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address these security vulnerabilities.

Data is provided by the National Vulnerability Database (NVD)
ArubanetworksArubaos Version >= 10.3.0.0 < 10.3.1.1
   ArubanetworksAp-103 Version-
   ArubanetworksAp-114 Version-
   ArubanetworksAp-115 Version-
   ArubanetworksAp-120 Version-
   ArubanetworksAp-121 Version-
   ArubanetworksAp-130 Version-
   ArubanetworksAp-135 Version-
   ArubanetworksAp-204 Version-
   ArubanetworksAp-205 Version-
   ArubanetworksAp-207 Version-
   ArubanetworksAp-214 Version-
   ArubanetworksAp-215 Version-
   ArubanetworksAp-224 Version-
   ArubanetworksAp-225 Version-
   ArubanetworksAp-303 Version-
   ArubanetworksAp-304 Version-
   ArubanetworksAp-305 Version-
   ArubanetworksAp-314 Version-
   ArubanetworksAp-315 Version-
   ArubanetworksAp-318 Version-
   ArubanetworksAp-324 Version-
   ArubanetworksAp-325 Version-
   ArubanetworksAp-334 Version-
   ArubanetworksAp-340 Version-
   ArubanetworksAp-370 Version-
   ArubanetworksAp-504 Version-
   ArubanetworksAp-505 Version-
   ArubanetworksAp-514 Version-
   ArubanetworksAp-515 Version-
   ArubanetworksAp-534 Version-
   ArubanetworksAp-535 Version-
   ArubanetworksAp-555 Version-
   ArubanetworksAp-635 Version-
   ArubanetworksAp-655 Version-
   ArubanetworksIap-103 Version-
   ArubanetworksIap-114 Version-
   ArubanetworksIap-115 Version-
   ArubanetworksIap-204 Version-
   ArubanetworksIap-205 Version-
   ArubanetworksIap-207 Version-
   ArubanetworksIap-224 Version-
   ArubanetworksIap-225 Version-
   ArubanetworksIap-304 Version-
   ArubanetworksIap-305 Version-
   ArubanetworksIap-314 Version-
   ArubanetworksIap-315 Version-
   ArubanetworksIap-318 Version-
   ArubanetworksIap-324 Version-
   ArubanetworksIap-325 Version-
   ArubanetworksIap-334 Version-
   ArubanetworksRap-108 Version-
   ArubanetworksRap-109 Version-
ArubanetworksInstant Version >= 6.4.0.0 < 6.4.4.8-4.2.4.21
   ArubanetworksAp-103 Version-
   ArubanetworksAp-114 Version-
   ArubanetworksAp-115 Version-
   ArubanetworksAp-120 Version-
   ArubanetworksAp-121 Version-
   ArubanetworksAp-130 Version-
   ArubanetworksAp-135 Version-
   ArubanetworksAp-204 Version-
   ArubanetworksAp-205 Version-
   ArubanetworksAp-207 Version-
   ArubanetworksAp-214 Version-
   ArubanetworksAp-215 Version-
   ArubanetworksAp-224 Version-
   ArubanetworksAp-225 Version-
   ArubanetworksAp-303 Version-
   ArubanetworksAp-304 Version-
   ArubanetworksAp-305 Version-
   ArubanetworksAp-314 Version-
   ArubanetworksAp-315 Version-
   ArubanetworksAp-318 Version-
   ArubanetworksAp-324 Version-
   ArubanetworksAp-325 Version-
   ArubanetworksAp-334 Version-
   ArubanetworksAp-340 Version-
   ArubanetworksAp-370 Version-
   ArubanetworksAp-504 Version-
   ArubanetworksAp-505 Version-
   ArubanetworksAp-514 Version-
   ArubanetworksAp-515 Version-
   ArubanetworksAp-534 Version-
   ArubanetworksAp-535 Version-
   ArubanetworksAp-555 Version-
   ArubanetworksAp-635 Version-
   ArubanetworksAp-655 Version-
   ArubanetworksIap-103 Version-
   ArubanetworksIap-114 Version-
   ArubanetworksIap-115 Version-
   ArubanetworksIap-204 Version-
   ArubanetworksIap-205 Version-
   ArubanetworksIap-207 Version-
   ArubanetworksIap-224 Version-
   ArubanetworksIap-225 Version-
   ArubanetworksIap-304 Version-
   ArubanetworksIap-305 Version-
   ArubanetworksIap-314 Version-
   ArubanetworksIap-315 Version-
   ArubanetworksIap-318 Version-
   ArubanetworksIap-324 Version-
   ArubanetworksIap-325 Version-
   ArubanetworksIap-334 Version-
   ArubanetworksRap-108 Version-
   ArubanetworksRap-109 Version-
ArubanetworksInstant Version >= 6.5.0.0 < 6.5.4.24
   ArubanetworksAp-103 Version-
   ArubanetworksAp-114 Version-
   ArubanetworksAp-115 Version-
   ArubanetworksAp-120 Version-
   ArubanetworksAp-121 Version-
   ArubanetworksAp-130 Version-
   ArubanetworksAp-135 Version-
   ArubanetworksAp-204 Version-
   ArubanetworksAp-205 Version-
   ArubanetworksAp-207 Version-
   ArubanetworksAp-214 Version-
   ArubanetworksAp-215 Version-
   ArubanetworksAp-224 Version-
   ArubanetworksAp-225 Version-
   ArubanetworksAp-303 Version-
   ArubanetworksAp-304 Version-
   ArubanetworksAp-305 Version-
   ArubanetworksAp-314 Version-
   ArubanetworksAp-315 Version-
   ArubanetworksAp-318 Version-
   ArubanetworksAp-324 Version-
   ArubanetworksAp-325 Version-
   ArubanetworksAp-334 Version-
   ArubanetworksAp-340 Version-
   ArubanetworksAp-370 Version-
   ArubanetworksAp-504 Version-
   ArubanetworksAp-505 Version-
   ArubanetworksAp-514 Version-
   ArubanetworksAp-515 Version-
   ArubanetworksAp-534 Version-
   ArubanetworksAp-535 Version-
   ArubanetworksAp-555 Version-
   ArubanetworksAp-635 Version-
   ArubanetworksAp-655 Version-
   ArubanetworksIap-103 Version-
   ArubanetworksIap-114 Version-
   ArubanetworksIap-115 Version-
   ArubanetworksIap-204 Version-
   ArubanetworksIap-205 Version-
   ArubanetworksIap-207 Version-
   ArubanetworksIap-224 Version-
   ArubanetworksIap-225 Version-
   ArubanetworksIap-304 Version-
   ArubanetworksIap-305 Version-
   ArubanetworksIap-314 Version-
   ArubanetworksIap-315 Version-
   ArubanetworksIap-318 Version-
   ArubanetworksIap-324 Version-
   ArubanetworksIap-325 Version-
   ArubanetworksIap-334 Version-
   ArubanetworksRap-108 Version-
   ArubanetworksRap-109 Version-
ArubanetworksInstant Version >= 8.6.0.0 < 8.6.0.19
   ArubanetworksAp-103 Version-
   ArubanetworksAp-114 Version-
   ArubanetworksAp-115 Version-
   ArubanetworksAp-120 Version-
   ArubanetworksAp-121 Version-
   ArubanetworksAp-130 Version-
   ArubanetworksAp-135 Version-
   ArubanetworksAp-204 Version-
   ArubanetworksAp-205 Version-
   ArubanetworksAp-207 Version-
   ArubanetworksAp-214 Version-
   ArubanetworksAp-215 Version-
   ArubanetworksAp-224 Version-
   ArubanetworksAp-225 Version-
   ArubanetworksAp-303 Version-
   ArubanetworksAp-304 Version-
   ArubanetworksAp-305 Version-
   ArubanetworksAp-314 Version-
   ArubanetworksAp-315 Version-
   ArubanetworksAp-318 Version-
   ArubanetworksAp-324 Version-
   ArubanetworksAp-325 Version-
   ArubanetworksAp-334 Version-
   ArubanetworksAp-340 Version-
   ArubanetworksAp-370 Version-
   ArubanetworksAp-504 Version-
   ArubanetworksAp-505 Version-
   ArubanetworksAp-514 Version-
   ArubanetworksAp-515 Version-
   ArubanetworksAp-534 Version-
   ArubanetworksAp-535 Version-
   ArubanetworksAp-555 Version-
   ArubanetworksAp-635 Version-
   ArubanetworksAp-655 Version-
   ArubanetworksIap-103 Version-
   ArubanetworksIap-114 Version-
   ArubanetworksIap-115 Version-
   ArubanetworksIap-204 Version-
   ArubanetworksIap-205 Version-
   ArubanetworksIap-207 Version-
   ArubanetworksIap-224 Version-
   ArubanetworksIap-225 Version-
   ArubanetworksIap-304 Version-
   ArubanetworksIap-305 Version-
   ArubanetworksIap-314 Version-
   ArubanetworksIap-315 Version-
   ArubanetworksIap-318 Version-
   ArubanetworksIap-324 Version-
   ArubanetworksIap-325 Version-
   ArubanetworksIap-334 Version-
   ArubanetworksRap-108 Version-
   ArubanetworksRap-109 Version-
ArubanetworksInstant Version >= 8.7.0.0 < 8.7.1.10
   ArubanetworksAp-103 Version-
   ArubanetworksAp-114 Version-
   ArubanetworksAp-115 Version-
   ArubanetworksAp-120 Version-
   ArubanetworksAp-121 Version-
   ArubanetworksAp-130 Version-
   ArubanetworksAp-135 Version-
   ArubanetworksAp-204 Version-
   ArubanetworksAp-205 Version-
   ArubanetworksAp-207 Version-
   ArubanetworksAp-214 Version-
   ArubanetworksAp-215 Version-
   ArubanetworksAp-224 Version-
   ArubanetworksAp-225 Version-
   ArubanetworksAp-303 Version-
   ArubanetworksAp-304 Version-
   ArubanetworksAp-305 Version-
   ArubanetworksAp-314 Version-
   ArubanetworksAp-315 Version-
   ArubanetworksAp-318 Version-
   ArubanetworksAp-324 Version-
   ArubanetworksAp-325 Version-
   ArubanetworksAp-334 Version-
   ArubanetworksAp-340 Version-
   ArubanetworksAp-370 Version-
   ArubanetworksAp-504 Version-
   ArubanetworksAp-505 Version-
   ArubanetworksAp-514 Version-
   ArubanetworksAp-515 Version-
   ArubanetworksAp-534 Version-
   ArubanetworksAp-535 Version-
   ArubanetworksAp-555 Version-
   ArubanetworksAp-635 Version-
   ArubanetworksAp-655 Version-
   ArubanetworksIap-103 Version-
   ArubanetworksIap-114 Version-
   ArubanetworksIap-115 Version-
   ArubanetworksIap-204 Version-
   ArubanetworksIap-205 Version-
   ArubanetworksIap-207 Version-
   ArubanetworksIap-224 Version-
   ArubanetworksIap-225 Version-
   ArubanetworksIap-304 Version-
   ArubanetworksIap-305 Version-
   ArubanetworksIap-314 Version-
   ArubanetworksIap-315 Version-
   ArubanetworksIap-318 Version-
   ArubanetworksIap-324 Version-
   ArubanetworksIap-325 Version-
   ArubanetworksIap-334 Version-
   ArubanetworksRap-108 Version-
   ArubanetworksRap-109 Version-
ArubanetworksInstant Version >= 8.10.0.0 < 8.10.0.2
   ArubanetworksAp-103 Version-
   ArubanetworksAp-114 Version-
   ArubanetworksAp-115 Version-
   ArubanetworksAp-120 Version-
   ArubanetworksAp-121 Version-
   ArubanetworksAp-130 Version-
   ArubanetworksAp-135 Version-
   ArubanetworksAp-204 Version-
   ArubanetworksAp-205 Version-
   ArubanetworksAp-207 Version-
   ArubanetworksAp-214 Version-
   ArubanetworksAp-215 Version-
   ArubanetworksAp-224 Version-
   ArubanetworksAp-225 Version-
   ArubanetworksAp-303 Version-
   ArubanetworksAp-304 Version-
   ArubanetworksAp-305 Version-
   ArubanetworksAp-314 Version-
   ArubanetworksAp-315 Version-
   ArubanetworksAp-318 Version-
   ArubanetworksAp-324 Version-
   ArubanetworksAp-325 Version-
   ArubanetworksAp-334 Version-
   ArubanetworksAp-340 Version-
   ArubanetworksAp-370 Version-
   ArubanetworksAp-504 Version-
   ArubanetworksAp-505 Version-
   ArubanetworksAp-514 Version-
   ArubanetworksAp-515 Version-
   ArubanetworksAp-534 Version-
   ArubanetworksAp-535 Version-
   ArubanetworksAp-555 Version-
   ArubanetworksAp-635 Version-
   ArubanetworksAp-655 Version-
   ArubanetworksIap-103 Version-
   ArubanetworksIap-114 Version-
   ArubanetworksIap-115 Version-
   ArubanetworksIap-204 Version-
   ArubanetworksIap-205 Version-
   ArubanetworksIap-207 Version-
   ArubanetworksIap-224 Version-
   ArubanetworksIap-225 Version-
   ArubanetworksIap-304 Version-
   ArubanetworksIap-305 Version-
   ArubanetworksIap-314 Version-
   ArubanetworksIap-315 Version-
   ArubanetworksIap-318 Version-
   ArubanetworksIap-324 Version-
   ArubanetworksIap-325 Version-
   ArubanetworksIap-334 Version-
   ArubanetworksRap-108 Version-
   ArubanetworksRap-109 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.61% 0.812
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.