← Vulnerability feed

Vulnerability record · CVE-2017-9000 · published 6 August 2018

CVE-2017-9000: Hp arubaos information exposure vulnerability

Hp · Arubaos

ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6.5.4 prior to 6.5.4.2, 8.x prior to 8.1.0.4 FIPS and non-FIPS versions of software are both affected equally is vulnerable to unauthenticated arbitrary file access. An unauthenticated user with network access to an Aruba mobility controller on TCP port 8080 or 8081 may be able to access arbitrary files stored on the mobility controller. Ports 8080 and 8081 are used for captive portal functionality and are listening, by default, on all IP interfaces of the mobility controller, including captive portal interfaces. The attacker could access files which could contain passwords, keys, and other sensitive information that could lead to full system compromise.

9.8 CVSS 3.0 Critical EPSS 5.7% · top 7.3% CWE-200 · Information exposure
9.8CVSS 3.0 base score, v2 5.0
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6.5.4 prior to 6.5.4.2, 8.x prior to 8.1.0.4 FIPS and non-FIPS versions of software are both affected equally is vulnerable to unauthenticated arbitrary file access. An unauthenticated user with network access to an Aruba mobility controller on TCP port 8080 or 8081 may be able to access arbitrary files stored on the mobility controller. Ports 8080 and 8081 are used for captive portal functionality and are listening, by default, on all IP interfaces of the mobility controller, including captive portal interfaces. The attacker could access files which could contain passwords, keys, and other sensitive information that could lead to full system compromise.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9000 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22782Hp arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 2.1%9.8CVE-2023-22783Hp arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 2.1%9.8CVE-2023-22784Hp arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 2.1%9.8CVE-2023-22785Hp arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 2.1%9.8CVE-2023-22786Hp arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 2.1%9.8CVE-2023-22779Hp arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 2.1%9.8CVE-2023-22780Hp arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 2.1%9.8CVE-2023-22781Hp arubaos classic buffer overflow vulnerabilityThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2017-9000), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.