Description
A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a port-stealing attack - may enable a bi-directional Machine-in-the-Middle (MitM) attack.
CVSS breakdown
CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)10.8.0.0 – 10.8.0.0
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)10.7.0.0 – 10.7.2.2
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)10.4.0.0 – 10.4.1.10
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)8.13.0.0 – 8.13.1.1
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)8.12.0.0 – 8.12.0.6
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)8.10.0.0 – 8.10.0.21