// For flags

CVE-2014-7299

Aruba Authentication Bypass / Insecure Transport / Tons Of Issues

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authentication, and obtain potentially sensitive information or add guest accounts, via an SSH session.

Vulnerabilidad no especificada en la interfaces de administración en ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, y 6.4.2.1-FIPS en los controladores Aruba permite a atacantes remotos evadir la autenticación, y obtener información potencialmente sensible o añadir cuentas de huéspedes, a través de una sesión SSH.

Multiple vulnerabilities were identified in Aruba AP, IAP and AMP devices. The vulnerabilities were discovered during a black box security assessment and therefore the vulnerability list should not be considered exhaustive. Several of the high severity vulnerabilities listed in this report are related to the Aruba proprietary PAPI protocol and allow remote compromise of affected devices.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-10-02 CVE Reserved
  • 2014-10-08 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arubanetworks
Search vendor "Arubanetworks"
Arubaos
Search vendor "Arubanetworks" for product "Arubaos"
6.3.11
Search vendor "Arubanetworks" for product "Arubaos" and version "6.3.11"
-
Affected
Arubanetworks
Search vendor "Arubanetworks"
Arubaos
Search vendor "Arubanetworks" for product "Arubaos"
6.3.11
Search vendor "Arubanetworks" for product "Arubaos" and version "6.3.11"
fips
Affected
Arubanetworks
Search vendor "Arubanetworks"
Arubaos
Search vendor "Arubanetworks" for product "Arubaos"
6.4.2.1
Search vendor "Arubanetworks" for product "Arubaos" and version "6.4.2.1"
-
Affected
Arubanetworks
Search vendor "Arubanetworks"
Arubaos
Search vendor "Arubanetworks" for product "Arubaos"
6.4.2.1
Search vendor "Arubanetworks" for product "Arubaos" and version "6.4.2.1"
fips
Affected