Description
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical system process, resulting in a denial-of-service condition.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating System (AOS)10.8.0.0 – 10.8.0.0
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating System (AOS)10.7.0.0 – 10.7.2.2
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating System (AOS)10.4.0.0 – 10.4.1.10