External risk intelligence

Aruba PAPI Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2022-37897

The vulnerability affects network infrastructure devices, specifically Aruba access points and SD-WAN products. It involves a management protocol (PAPI) reachable over the network. While management protocols are sometimes restricted, these devices are commonly deployed at the edge of networks, and management ports on such appliances are frequently accessible to internal or adjacent network segments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A command injection vulnerability in Aruba Networks' management protocol could allow unauthenticated remote code execution, potentially affecting network infrastructure devices. Understanding its relevance to our deployed Aruba systems is key.

  • Unauthenticated remote code execution is possible.
  • Potential for unauthorized system control exists.
  • Confirm Aruba device relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can send specially crafted network packets to a management port on vulnerable Aruba devices. This can lead to the execution of arbitrary commands with high privileges on the device's operating system.

  • Unauthenticated network access required.
  • Specially crafted packets to UDP port 8211 trigger vulnerability.
  • Allows privileged code execution on device.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary commands on the affected devices by sending specially crafted network packets. When supported by the advisory, this could impact the underlying operating system of Aruba network devices.

  • System commands could be executed.
  • Network packets can trigger execution.
  • Device compromise is a realistic consequence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical command injection vulnerability in Aruba's PAPI protocol could allow unauthenticated remote code execution on affected access points and SD-WAN devices. Identifying the deployed instances, confirming their network reachability and business criticality, and then engaging the accountable Aruba or network infrastructure owner is the essential first step. Planning remediation should follow based on this risk assessment, potentially involving vendor coordination or temporary mitigations if immediate patching is not feasible.

  • Network and Aruba device owners are responsible.
  • Verify PAPI UDP port 8211 reachability.
  • Plan remediation and coordinate with vendor.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the software affected by CVE-2022-37897?

This vulnerability affects Aruba Networks' SD-WAN and ArubaOS software. These platforms power enterprise-grade network infrastructure, including access points and gateway appliances used to manage connectivity and traffic across corporate networks.

What does command injection mean in this context?

Command injection is a security weakness, classified as CWE-78, where an application improperly handles user-supplied data. In this specific CVE, the PAPI management protocol fails to safely process incoming packets, allowing an attacker to inject and execute their own unauthorized system commands with high-level privileges.

How is this vulnerability triggered?

An attacker triggers this by sending specially crafted network packets to UDP port 8211, which Aruba devices use for the PAPI management protocol. The vulnerability does not require authentication; however, the attacker must have network reachability to the device on that specific management port to initiate the malicious command execution.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates this is a high-relevance issue because it impacts infrastructure devices often positioned at network edges. Because PAPI management ports on these devices are frequently reachable from internal or adjacent network segments, they are more accessible to potential threats than isolated systems.

How should I respond to this vulnerability?

First, identify if you have any affected Aruba SD-WAN or ArubaOS versions deployed in your environment. Confirm the network reachability of UDP port 8211 on those devices. Once identified, coordinate with your network infrastructure team to verify your current version status and prioritize applying the official vendor updates.