A flaw in an authorization component allows for unauthorized access to the Wireless LAN through a Captive Portal, VPN, and administrative access using either the web-based administration or the command line interface. This vulnerability affects all versions of the Aruba Controller beginning with version 2.3.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54407/n.runs-SA-2007.001.txt
Source: https://packetstormsecurity.com/files/54407/n.runs-SA-2007.001.txt.html