Critical severity9.8NVD Advisory· Published Jan 31, 2020· Updated Jun 17, 2026
CVE-2016-2031
CVE-2016-2031
Description
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:arubanetworks:aruba_instant:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:arubanetworks:aruba_instant:*:*:*:*:*:*:*:*range: <4.1.3.0
- cpe:2.3:a:arubanetworks:aruba_instant:4.2.3.1:*:*:*:*:*:*:*
- cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
- cpe:2.3:o:siemens:scalance_w1750d_firmware:*:*:*:*:*:*:*:*
- Aruba/Instatedescription
- Range: <4.1.3.0, <4.2.3.1
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/136997/Aruba-Authentication-Bypass-Insecure-Transport-Tons-Of-Issues.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2016/May/19nvdExploitMailing ListThird Party Advisory
- www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-004.txtnvdVendor Advisory
- cert-portal.siemens.com/productcert/pdf/ssa-431802.pdfnvdThird Party Advisory
- www.securityfocus.com/bid/90207nvdBroken Link
News mentions
0No linked articles in our index yet.