This vulnerability is currently undergoing analysis and not all information is available. Please check back soon to view the completed vulnerability summary.
ArubaOS, all versions prior to 184.108.40.206, 6.4 prior to 220.127.116.11, 6.5.x prior to 18.104.22.168, 6.5.2, 6.5.3 prior to 22.214.171.124, 6.5.4 prior to 126.96.36.199, 8.x prior to 188.8.131.52 FIPS and non-FIPS versions of software are both affected equally is vulnerable to unauthenticated arbitrary file access. An unauthenticated user with network access to an Aruba mobility controller on TCP port 8080 or 8081 may be able to access arbitrary files stored on the mobility controller. Ports 8080 and 8081 are used for captive portal functionality and are listening, by default, on all IP interfaces of the mobility controller, including captive portal interfaces. The attacker could access files which could contain passwords, keys, and other sensitive information that could lead to full system compromise.
Description Last Modified:
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because
they may have information that would be of interest to you. No inferences should be drawn on account of other sites
being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.
NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further,
NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about
this page to email@example.com.
1 change record found
- show changes
CVE Modified by MITRE -
8/7/2018 9:29:03 PM
http://www.securitytracker.com/id/1039580 [No Types Assigned]
CVE Dictionary Entry:
NVD Published Date:
NVD Last Modified: