ArubaOS 8.13.2.0 Pre-Auth XXE → OOB SSRF & Internal Port Scan on Port 32000 | CWE-611 HPE Bugcrowd

ArubaOS 8.13.2.0 ships default-xml-api AAA profile on port 32000/TCP with no authentication. The XML parser processes SYSTEM entity declarations and resolves them outbound. Four independent evidence items: wire-level pcap confirms controller TCP connection to attacker listener, target sshd log shows 127.0.0.1-sourced GET request impossible to produce externally, attacker HTTP server logged three DTD fetches at 02:33/02:36/02:38, nine internal ports confirmed open via dialog success responses. CWE-611. CVSS 9.3 Critical. Bugcrowd closed as theoretical. No fix issued.

June 1, 2026 · 4 min · JM00NJ
ArubaOS 8.13.2.0 Pre-Auth XXE → OOB SSRF & Internal Port Scan on Port 32000 | CWE-611 HPE Bugcrowd
DigitalOcean Referral Badge