Daniel Jensen: Hunting Vulnerabilities in Aruba Networking Devices
A DEF CON 30 talk about vulnerability research in enterprise networking products from Aruba Networks. Over several years of analysis, the speaker discovered multiple security flaws that allow arbitrary code execution on these devices.
The talk explores the discovered vulnerabilities, including pre-authentication bugs, exploitation chains, and several unexpected attack surfaces.
The talk explores the discovered vulnerabilities, including pre-authentication bugs, exploitation chains, and several unexpected attack surfaces.