Back

CVE-2018-7081

CRITICAL

A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a process crash or to execute arbitrary code within the underlying operating system with full system privileges. Such an attack could lead to complete system compromise. The ability to transmit traffic to an IP interface on the mobility controller is required to carry out an attack. The attack leverages the PAPI protocol (UDP port 8211). If the mobility controller is only bridging L2 traffic to an uplink and does not have an IP address that is accessible to the attacker, it cannot be attacked.

Published: Sep 13, 2019 Modified: Jun 17, 2026
CWE-20

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (6)

Vendor Product Version
arubanetworks arubaos * < 6.4.4.21
arubanetworks arubaos * ≥ 6.5.0.0 < 6.5.4.13
arubanetworks arubaos * ≥ 8.0.0.0 < 8.2.2.6
arubanetworks arubaos * ≥ 8.3.0.0 < 8.3.0.7
arubanetworks arubaos * ≥ 8.4.0.0 < 8.4.0.3
arubanetworks arubaos * ≥ 8.4.0.4 < 8.5.0.0

GitHub Security Advisory GHSA-v23q-qg5x-p624

A remote code execution vulnerability is present in network-listening components in some versions...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.85%

Top 7% most likely to be exploited

Threat Score 41 / 100

Data Sources

NVD EPSS GitHub