IETF
RFC
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
Official registry publication history is available at rfc, but registry activity is not a publisher support boundary.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2024-3596 | 9 Jul 2024 | 2865 | This vulnerability is fixed in the following HPE Aruba Networking products’ software releases - - AirWave Management Platform - 8.3.0.3 and above - - ClearPass Policy Manager - 6.12.2 and above - 6.11.9 and above - In addition, the following steps need to be taken to enable the RADIUS Message-Authenticator on ClearPass Navigate to Administration > Server Manager > Server Configuration screen, select each server individually to enable Message-Authenticator support. On the server screen, navigate to "Service Parameters" tab, select the “Radius server” service. Under the Security header, modify the parameters Require Message-Authenticator from NAD = yes Require Message-Authenticator from Proxy Server = yes Save the changes. This will then restart the service with the requirement that the Message-Authenticator be transmitted, or the request will not be processed. - - Switches running AOS-CX - 10.14.1010 and above - 10.13.1040 and above - 10.10.1140 and above - - WLAN Gateways and SD-WAN Gateways running AOS-10 - AOS-10.6.0.3 and above - AOS-10.4.1.4 and above - - Mobility Controllers running AOS-8 - AOS-8.12.0.2 and above - AOS-8.10.0.14 and above - - Aruba Fabric Composer - 7.1.1 and above - - EdgeConnect SD-WAN Orchestrator - Use the following link to find instructions for addressing CVE-2024-3596: https://www.arubanetworks.com/techdocs/sdwan-PDFs/docs/advisories/or ch_resolution_to_cve-2024-3596_latest.pdf - - HPE Networking Instant On - Switch series 1930 and 1960 firmware version 3.1.0 for local mode - Upgrade Access Points firmware to version 3.1.0 and use option "Require RADIUS Message-Authenticator" if using an external guest portal. Software updates for this vulnerability fix in the other affected products are forthcoming. This advisory will be updated as details on the respective product’s software versions with this vulnerability fix become available. For more information about HPE Aruba Networking products End of Support policy visit: https://networkingsupport.hpe.com/end-of-life | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.