CVE-2016-2032
Aruba Authentication Bypass / Insecure Transport / Tons Of Issues
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672
Se presenta una vulnerabilidad en Aruba AirWave Management Platform versiones 8.x anteriores a 8.2, en la interfaz de administración de un componente de un sistema subyacente llamado RabbitMQ, lo que podría permitir a un usuario malicioso obtener información confidencial. Esta interfaz escucha sobre los puertos TCP 15672 y 55672
Multiple vulnerabilities were identified in Aruba AP, IAP and AMP devices. The vulnerabilities were discovered during a black box security assessment and therefore the vulnerability list should not be considered exhaustive. Several of the high severity vulnerabilities listed in this report are related to the Aruba proprietary PAPI protocol and allow remote compromise of affected devices.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-01-22 CVE Reserved
- 2016-05-06 CVE Published
- 2024-06-28 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.google.com/about/appsecurity/research | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/136997/Aruba-Authentication-Bypass-Insecure-Transport-Tons-Of-Issues.html | 2024-08-05 | |
http://seclists.org/fulldisclosure/2016/May/19 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-005.txt | 2021-05-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arubanetworks Search vendor "Arubanetworks" | Airwave Search vendor "Arubanetworks" for product "Airwave" | >= < 8.2.0.0 Search vendor "Arubanetworks" for product "Airwave" and version " >= < 8.2.0.0" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Aruba Instant Search vendor "Arubanetworks" for product "Aruba Instant" | < 4.1.3.0 Search vendor "Arubanetworks" for product "Aruba Instant" and version " < 4.1.3.0" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Aruba Instant Search vendor "Arubanetworks" for product "Aruba Instant" | 4.2.3.1 Search vendor "Arubanetworks" for product "Aruba Instant" and version "4.2.3.1" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | * | - |
Affected
|