Executive brief
A vulnerability exists in the operating systems used by Aruba networking devices, specifically within the component that handles network protocols. An attacker can exploit this flaw by sending malicious network traffic to the device without needing any login credentials. If successful, the attack crashes a critical system process, causing the networking equipment to stop functioning and disrupting network connectivity for the organization.
Technical details
A denial-of-service vulnerability exists in the protocol-handling component of HPE Aruba Networking AOS-8 and AOS-10. The flaw is rooted in improper input validation (CWE-20) when processing incoming network messages. An unauthenticated, remote attacker can exploit this by sending specially crafted packets to the affected service. Successful exploitation causes the termination of a critical system process, leading to a complete denial-of-service (DoS) state for the affected device. The vulnerability is reachable over the network without user interaction.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: advisory: Initial disclosure by HPE/Aruba