{"api_version":"v1","generated_at":"2026-10-08T07:00:00+00:00","product":{"cve_count":1,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-ietf-rfc-2c851e1c6eb6","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/rfc","name":"RFC","next_cursor":null,"observations":[{"affected":"2865","affected_versions_present":true,"cve_id":"CVE-2024-3596","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-3596","fixed":"This vulnerability is fixed in the following HPE Aruba Networking products\u2019 software releases - - AirWave Management Platform - 8.3.0.3 and above - - ClearPass Policy Manager - 6.12.2 and above - 6.11.9 and above - In addition, the following steps need to be taken to enable the RADIUS Message-Authenticator on ClearPass Navigate to Administration > Server Manager > Server Configuration screen, select each server individually to enable Message-Authenticator support. On the server screen, navigate to \"Service Parameters\" tab, select the \u201cRadius server\u201d service. Under the Security header, modify the parameters Require Message-Authenticator from NAD = yes Require Message-Authenticator from Proxy Server = yes Save the changes. This will then restart the service with the requirement that the Message-Authenticator be transmitted, or the request will not be processed. - - Switches running AOS-CX - 10.14.1010 and above - 10.13.1040 and above - 10.10.1140 and above - - WLAN Gateways and SD-WAN Gateways running AOS-10 - AOS-10.6.0.3 and above - AOS-10.4.1.4 and above - - Mobility Controllers running AOS-8 - AOS-8.12.0.2 and above - AOS-8.10.0.14 and above - - Aruba Fabric Composer - 7.1.1 and above - - EdgeConnect SD-WAN Orchestrator - Use the following link to find instructions for addressing CVE-2024-3596: https://www.arubanetworks.com/techdocs/sdwan-PDFs/docs/advisories/or ch_resolution_to_cve-2024-3596_latest.pdf - - HPE Networking Instant On - Switch series 1930 and 1960 firmware version 3.1.0 for local mode - Upgrade Access Points firmware to version 3.1.0 and use option \"Require RADIUS Message-Authenticator\" if using an external guest portal. Software updates for this vulnerability fix in the other affected products are forthcoming. This advisory will be updated as details on the respective product\u2019s software versions with this vulnerability fix become available. For more information about HPE Aruba Networking products End of Support policy visit: https://networkingsupport.hpe.com/end-of-life","last_modified":"2026-06-09T09:01:52.617Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2024-07-09T12:02:53.001Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"IETF"}}
