Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-33516", "assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0", "state": "PUBLISHED", "assignerShortName": "hpe", "dateReserved": "2024-04-23T14:21:30.435Z", "datePublished": "2024-05-01T16:30:59.727Z", "dateUpdated": "2024-08-02T02:36:04.056Z"}, "containers": {"cna": {"affected": [{"defaultStatus": "affected", "product": "Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central", "vendor": "Hewlett Packard Enterprise (HPE)", "versions": [{"status": "affected", "version": "ArubaOS 10.5.x.x: 10.5.1.0 and below"}, {"status": "affected", "version": "ArubaOS 10.4.x.x: 10.4.1.0 and below"}, {"status": "affected", "version": "ArubaOS 8.11.x.x: 8.11.2.1 and below"}, {"status": "affected", "version": "ArubaOS 8.10.x.x: 8.10.0.10 and below"}]}], "credits": [{"lang": "en", "type": "reporter", "user": "00000000-0000-4000-9000-000000000000", "value": "Chancen"}], "descriptions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "<p>An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.</p>"}], "value": "An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.\n\n"}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1"}, "format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "providerMetadata": {"orgId": "eb103674-0d28-4225-80f8-39fb86215de0", "shortName": "hpe", "dateUpdated": "2024-05-01T16:30:59.727Z"}, "references": [{"url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-004.txt"}], "source": {"discovery": "UNKNOWN"}, "x_generator": {"engine": "Vulnogram 0.1.0-dev"}}, "adp": [{"problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-121", "lang": "en", "description": "CWE-121 Stack-based Buffer Overflow"}]}], "affected": [{"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:8.10.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "8.10.0.0", "status": "affected", "lessThan": "8.10.0.10", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:10.5.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "10.5.0.0", "status": "affected", "lessThan": "10.5.1.0", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:10.4.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "10.4.0.0", "status": "affected", "lessThan": "10.4.1.0", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:8.11.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "8.11.0.0", "status": "affected", "lessThan": "8.11.2.1", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:10.3.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "10.3.0.0", "status": "affected", "lessThan": "10.4.0.0", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:8.9.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "8.9.0.0", "status": "affected", "lessThan": "8.10.0.0", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:8.8.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "8.8.0.0", "status": "affected", "lessThan": "8.9.0.0", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:8.7.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "8.7.0.0", "status": "affected", "lessThan": "8.8.0.0", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:8.6.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "8.6.0.0", "status": "affected", "lessThan": "8.7.0.0", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:6.5.4.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "6.5.4.0", "status": "affected", "lessThan": "6.5.5.0", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "sd-wan", "cpes": ["cpe:2.3:a:arubanetworks:sd-wan:8.7.0.0:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "8.7.0.0", "status": "affected", "lessThan": "*", "versionType": "custom"}]}, {"vendor": "arubanetworks", "product": "sd-wan", "cpes": ["cpe:2.3:a:arubanetworks:sd-wan:8.6.0.4:*:*:*:*:*:*:*"], "defaultStatus": "affected", "versions": [{"version": "8.6.0.4", "status": "affected", "lessThan": "*", "versionType": "custom"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-05-02T15:59:36.938795Z", "id": "CVE-2024-33516", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-07-24T18:56:28.721Z"}}, {"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T02:36:04.056Z"}, "title": "CVE Program Container", "references": [{"url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-004.txt", "tags": ["x_transferred"]}]}]}}