CVE-2024-25615 — Uncontrolled Resource Consumption in Arubaos
Severity
5.3MEDIUMNVD
EPSS
0.1%
top 84.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 5
Description
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4
Affected Packages2 packages
▶CVEListV5hewlett_packard_enterprise/arubaos_wi-fi_controllers_and_campus_remote_access_points4 versions+3
🔴Vulnerability Details
2GHSA▶
GHSA-54wh-fwqq-m49j: An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8↗2024-03-05
CVEList▶
CVE-2024-25615: An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8↗2024-03-05