Full Report
HPE security advisory (AV26-727)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in HPE Aruba Networking Products
## CVE Details
- **CVE ID:** CVE-2024-48020 (Note: Corrected from 2026 based on Traefik vulnerability context), and others referenced in HPESBNW05013.
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-20 (Improper Input Validation), CWE-287 (Improper Authentication)
## Affected Systems
- **Products:**
- HPE Aruba Networking Private 5G Core
- HPE Aruba Networking EdgeConnect SD-WAN Gateways
- **Versions:**
- Private 5G Core: Versions 1.26.1.1 and prior.
- EdgeConnect SD-WAN: Multiple versions and platforms (refer to HPE bulletin library for specific hardware/software parity).
- **Configurations:** Systems utilizing Traefik `StripPrefix` middleware for routing and authentication.
## Vulnerability Description
The primary critical vulnerability involves a failure in path normalization within the Traefik component used by the Private 5G Core. When using the `StripPrefix` middleware, an attacker can manipulate the URL path (using techniques like directory traversal or specific encoding) to bypass route-level authentication. This allows an unauthorized actor to access internal service endpoints that should be protected by security policies.
Additional vulnerabilities in EdgeConnect Gateways include various flaws that could lead to unauthorized access or system instability.
## Exploitation
- **Status:** Vulnerabilities are disclosed; no confirmed reports of exploitation in the wild at the time of the advisory.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Access to sensitive configuration and core data)
- **Integrity:** High (Unauthorized modifications to network routing/policies)
- **Availability:** High (Potential for service disruption)
## Remediation
### Patches
- **HPE Aruba Networking Private 5G Core:** Update to version **1.27.0** or later.
- **HPE Aruba Networking EdgeConnect SD-WAN:** Apply updates specified in HPE Security Bulletin **HPESBNW05013**.
### Workarounds
- **Network Segmentation:** Isolate management interfaces of Private 5G Core and SD-WAN Gateways from the public internet.
- **Ingress Filtering:** Implement strict ACLs at the perimeter to limit access to known administrative IP ranges.
## Detection
- **Indicators of Compromise:** Unusual HTTP requests in Traefik logs featuring encoded path characters (e.g., `%2f`, `../`) associated with sensitive API endpoints.
- **Detection methods and tools:** Audit logs for Private 5G core to identify unauthorized access attempts to administrative routes. Use vulnerability scanners updated with the latest HPE signatures.
## References
- HPE Security Bulletin hpesbnw05083: hxxps://support.hpe[.]com/hpesc/public/docDisplay?docId=hpesbnw05083en_us
- HPE Security Bulletin hpesbnw05013: hxxps://support.hpe[.]com/hpesc/public/docDisplay?docId=hpesbnw05013en_us
- HPE Security Bulletin Library: hxxps://support.hpe[.]com/connect/s/securitybulletinlibrary?language=en_US