CVE-2008-7023

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
21/08/2009
Last modified:
09/04/2025

Description

Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:arubanetworks:aruba_mobility_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:3.3.1.16:*:*:*:*:*:*:*