Critical severity9.8NVD Advisory· Published May 14, 2024· Updated Jun 17, 2026
CVE-2024-31470
CVE-2024-31470
Description
There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Affected products
4- Hewlett Packard Enterprise (HPE)/AOS-8 Instant and AOS-10 APv5Range: 10.5.0.0
Patches
Vulnerability mechanics
References
2- www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txtnvdBroken LinkVendor Advisory
- support.hpe.com/hpesc/public/docDisplaynvd
News mentions
0No linked articles in our index yet.