CVE Vulnerabilities

CVE-2024-25616

Published: Mar 05, 2024 | Modified: Jul 28, 2025
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.

Affected Software

Name Vendor Start Version End Version
Arubaos Arubanetworks 8.10.0.0 (including) 8.10.0.10 (excluding)
Arubaos Arubanetworks 8.11.0.0 (including) 8.11.2.1 (excluding)
Arubaos Arubanetworks 10.4.0.0 (including) 10.4.1.0 (excluding)
Arubaos Arubanetworks 10.5.0.0 (including) 10.5.1.0 (excluding)

References