// For flags

CVE-2016-2032

Aruba Authentication Bypass / Insecure Transport / Tons Of Issues

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672

Se presenta una vulnerabilidad en Aruba AirWave Management Platform versiones 8.x anteriores a 8.2, en la interfaz de administración de un componente de un sistema subyacente llamado RabbitMQ, lo que podría permitir a un usuario malicioso obtener información confidencial. Esta interfaz escucha sobre los puertos TCP 15672 y 55672

Multiple vulnerabilities were identified in Aruba AP, IAP and AMP devices. The vulnerabilities were discovered during a black box security assessment and therefore the vulnerability list should not be considered exhaustive. Several of the high severity vulnerabilities listed in this report are related to the Aruba proprietary PAPI protocol and allow remote compromise of affected devices.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-01-22 CVE Reserved
  • 2016-05-06 CVE Published
  • 2024-06-28 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arubanetworks
Search vendor "Arubanetworks"
Airwave
Search vendor "Arubanetworks" for product "Airwave"
>= < 8.2.0.0
Search vendor "Arubanetworks" for product "Airwave" and version " >= < 8.2.0.0"
-
Affected
Arubanetworks
Search vendor "Arubanetworks"
Aruba Instant
Search vendor "Arubanetworks" for product "Aruba Instant"
< 4.1.3.0
Search vendor "Arubanetworks" for product "Aruba Instant" and version " < 4.1.3.0"
-
Affected
Arubanetworks
Search vendor "Arubanetworks"
Aruba Instant
Search vendor "Arubanetworks" for product "Aruba Instant"
4.2.3.1
Search vendor "Arubanetworks" for product "Aruba Instant" and version "4.2.3.1"
-
Affected
Arubanetworks
Search vendor "Arubanetworks"
Arubaos
Search vendor "Arubanetworks" for product "Arubaos"
*-
Affected