HomeSecurityHackers breached Aruba Central with stolen access key

Hackers breached Aruba Central with stolen access key

HPE has revealed that data repositories for its Aruba Central monitoring platform were compromised, allowing hackers to access data collected about monitoring devices and their locations.

Aruba Central

See also: Iranian hackers attack ISPs with new enhanced malware

Aruba Central is a cloud networking solution that allows administrators to manage large networks and assets from a single dashboard.

HPE revealed that hackers obtained an “access key” that allowed them to view customer data stored in its Aruba central environment. The malicious actors had access for 18 days from October 9, 2021, to October 27, when HPE revoked the key.

The exposed repositories contained two datasets, one for network analysis and the other for Aruba Central's "Contract Tracking" feature.

The network analytics dataset exposed in these repositories included MAC addresses, IP addresses, operating systems, hostname, and for authenticated Wi-Fi networks, an individual's username.

The contract detection dataset also included the date, time, and Wi-Fi access points that users connected to, potentially allowing the threat actor to track the general location of users.

As FAQ mentioned the word "buckets" multiple times, the threat actor likely obtained the access key for a storage bucket used by the platform.

See also: Microsoft: Fixes Excel zero-day used in attacks

Hackers

After conducting an investigation into the breach, HPE concluded that:

  • No more than 30 days of data is stored, as data in the network analysis and contact tracing functions of the Aruba Central environment is automatically deleted every 30 days.
  • The environment included personal data, but not sensitive personal data. Personal data includes MAC addresses, IP addresses, device operating system type and hostname, and some usernames. Contact tracing data also included the name of the access point (AP), proximity, and length of time connected to that access point.
  • The likelihood of access to users' personal data is extremely low, based on extensive analysis of access and traffic patterns.
  • Security-sensitive information was not compromised and therefore there is no perceived need to change passwords, change keys, or modify network configuration.

See also: How to check what data Twitter has about you?

HPE states that they are changing how they protect and store access keys to prevent future incidents.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS