HPE ArubaOS
cpe:2.3:o:hp:arubaos:*:*:*:*:*:*:*, +1 more
- <= 10.8.0.0
- <= 10.7.2.2
- <= 10.4.1.10
- <= 8.13.1.1
- <= 8.12.0.6
- <= 8.10.0.21
- ~10.6
- ~10.5
- ~10.3
- ~8.12
- ~8.11
- ~8.9
- ~8.8
- ~8.7
- ~8.6
- ~6.5.4
- ~8.7.0.0-2.3.0
- ~8.6.0.4-2.2
A session management vulnerability exists in HPE Aruba Networking Operating System AOS-8. This vulnerability allows previously authenticated users to retain network access even after their accounts have been administratively disabled. When credentials are revoked, existing sessions are not invalidated, enabling continued access until the session expires. This behavior could be exploited by an attacker with compromised credentials to maintain unauthorized access despite account deactivation.
Exploitation of this vulnerability could lead to unauthorized access to network resources, allowing an attacker to interact with the network as if they were a legitimate user, even after their account has been disabled.
To address this vulnerability, users should delete the affected account using the 'aaa user delete' command. For more information, consult the HPE Aruba Networking Support Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.