9.8

CVE-2023-22751

Warning

There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211).  Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

Data is provided by the National Vulnerability Database (NVD)
ArubanetworksSd-wan Version >= 8.7.0.0-2.3.0.0 <= 8.7.0.0-2.3.0.8
ArubanetworksArubaos Version >= 8.6.0.0 <= 8.6.0.19
ArubanetworksArubaos Version >= 8.10.0.0 <= 8.10.0.4
ArubanetworksArubaos Version >= 10.3.0.0 <= 10.3.1.0
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.62% 0.801
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security-alert@hpe.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.