{ "data_type": "CVE", "data_format": "MITRE", "data_version": "4.0", "CVE_data_meta": { "ID": "CVE-2020-24634", "ASSIGNER": "security-alert@hpe.com", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "n/a", "product": { "product_data": [ { "product_name": "Aruba 9000 Gateway", "version": { "version_data": [ { "version_value": "2.1.0.1" }, { "version_value": "2.2.0.0 and below" } ] } }, { "product_name": "Aruba 7000 Series Mobility Controllers", "version": { "version_data": [ { "version_value": "6.4.4.23" }, { "version_value": "6.5.4.17" }, { "version_value": "8.2.2.9" }, { "version_value": "8.3.0.13" }, { "version_value": "8.5.0.10" }, { "version_value": "8.6.0.5" }, { "version_value": "8.7.0.0 and below" } ] } }, { "product_name": "Aruba 7200 Series Mobility Controllers", "version": { "version_data": [ { "version_value": "6.4.4.23" }, { "version_value": "6.5.4.17" }, { "version_value": "8.2.2.9" }, { "version_value": "8.3.0.13" }, { "version_value": "8.5.0.10" }, { "version_value": "8.6.0.5" }, { "version_value": "8.7.0.0 and below" } ] } } ] } } ] } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "remote injection of arbitrary commands" } ] } ] }, "references": { "reference_data": [ { "refsource": "CONFIRM", "name": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04072en_us", "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04072en_us" } ] }, "description": { "description_data": [ { "lang": "eng", "value": "An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below." } ] } }