Description
A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for the interception or modification of traffic intended for the legitimate network gateway via a Machine-in-the-Middle (MitM) position.
CVSS breakdown
CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)10.8.0.0 – 10.8.0.0
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)10.7.0.0 – 10.7.2.2
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)10.4.0.0 – 10.4.1.10
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)8.13.0.0 – 8.13.1.1
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)8.12.0.0 – 8.12.0.6
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)8.10.0.0 – 8.10.0.21