CVE-2008-7023
Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- arubanetworks/aruba mobility controller · arubanetworks/arubaos
- Source
- cve@mitre.org
References
- http://osvdb.org/51731
- http://www.securityfocus.com/archive/1/496604/100/0/threaded
- http://www.securityfocus.com/archive/1/496622/100/0/threaded
- http://www.securityfocus.com/bid/31336
- http://osvdb.org/51731
- http://www.securityfocus.com/archive/1/496604/100/0/threaded
- http://www.securityfocus.com/archive/1/496622/100/0/threaded
- http://www.securityfocus.com/bid/31336
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.