VULNERABILITY INTELLIGENCE
CVE-2017-9003
CVSS score7.5 HIGH
EPSS probability3.54%
CISA KEVNot currently listed
Published2018-08-06
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Multiple memory corruption flaws are present in ArubaOS which could allow an unauthenticated user to crash ArubaOS processes. With sufficient time and effort, it is possible these vulnerabilities could lead to the ability to execute arbitrary code - remote code execution has not yet been confirmed.
Weakness classification
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Primary references
- security-alert@hpe.com — Vendor Advisory
- security-alert@hpe.com — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry