Aruba Mobility Controllers use X.509 certificates to protect access to the web management interface and to provide secure wireless authentication, such as TLS, TTLS, PEAP, and Aruba-specific Captive Portal. By default, the controller uses a built-in certificate that is shared by all deployed units across all customers. This is broken for the obvious reasons.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/70235/aruba-cert.txt
Source: https://packetstormsecurity.com/files/70235/aruba-cert.txt.html