
CVE-2023-45617
https://notcve.org/view.php?id=CVE-2023-45617
14 Nov 2023 — There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point. Existen vulnerabilidades de eliminación de archivos arbitrarios en CLI Service al que accede PAPI (el protocolo de administración de puntos d... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt •

CVE-2023-45616
https://notcve.org/view.php?id=CVE-2023-45616
14 Nov 2023 — There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. Existe una vulnerabilidad de desbordamiento del búfer en AirWave Client Service subyacente que podría c... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-45615
https://notcve.org/view.php?id=CVE-2023-45615
14 Nov 2023 — There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. Existen vulnerabilidades de desbordamiento del búfer en CLI Service subyacente que podrían provocar la ejecució... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-45614
https://notcve.org/view.php?id=CVE-2023-45614
14 Nov 2023 — There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. Existen vulnerabilidades de desbordamiento del búfer en CLI Service subyacente que podrían provocar la ejecució... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-35982 – Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
https://notcve.org/view.php?id=CVE-2023-35982
25 Jul 2023 — There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated ... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-009.txt • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-35981 – Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
https://notcve.org/view.php?id=CVE-2023-35981
25 Jul 2023 — There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated ... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-009.txt • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-35980 – Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
https://notcve.org/view.php?id=CVE-2023-35980
25 Jul 2023 — There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system. There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated ... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-009.txt • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-22791 – Aruba InstantOS and ArubaOS 10 Sensitive Information Disclosure
https://notcve.org/view.php?id=CVE-2023-22791
08 May 2023 — A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. The scenarios in which this disclosure of potentially sensitive information can occur are complex and depend on factors that are beyond the control of the attacker. A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-006.txt •

CVE-2023-22790 – Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface
https://notcve.org/view.php?id=CVE-2023-22790
08 May 2023 — Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as ... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-006.txt • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2023-22789 – Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface
https://notcve.org/view.php?id=CVE-2023-22789
08 May 2023 — Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as ... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-006.txt • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •