Security Advisory

CVE-2008-7023

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-08-21 14:00:00
Last updated 2024-08-07 11:49:02
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.