CVE-2024-25616: Arubanetworks Arubaos
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.
Affected products
- Arubanetworks Arubaos: from 8.10.0.0, before 8.10.0.10 (fixed in 8.10.0.10); from 8.11.0.0, before 8.11.2.1 (fixed in 8.11.2.1); from 10.4.0.0, before 10.4.1.0 (fixed in 10.4.1.0); from 10.5.0.0, before 10.5.1.0 (fixed in 10.5.1.0)
Published 2024-03-05. Last modified 2026-06-17.