CVE-2024-42501
HIGHAruba OS <= 10.6.0.2, <= 10.6.0.0, <= 10.4.0.0, <= 8.10.0.13, <= 8.12.0.0, <= 8.12.0.1 - Authenticated Path Traversal
Title source: llmDescription
An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.
References (1)
Core 1
Core References
Scores
CVSS v3
7.2
EPSS
0.0114
EPSS Percentile
62.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (7)
Hewlett Packard Enterprise (HPE)/Aruba OS
Version 10.3.0.0: 10.4.0.0 and below - <=10.4.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS
Version 10.5.0.0: 10.6.0.0 and below - <=10.6.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS
Version 10.6.0.0: 10.6.0.2 and below - <=10.6.0.2
Hewlett Packard Enterprise (HPE)/Aruba OS
Version 6.5.4.0: 8.9.0.0 and below - <=8.9.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS
Version 8.10.0.0: 8.10.0.13 and below - <=8.10.0.13
Hewlett Packard Enterprise (HPE)/Aruba OS
Version 8.11.0.0: 8.12.0.0 and below - <=8.12.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS
Version 8.12.0.0: 8.12.0.1 and below - <=8.12.0.1
Published
Sep 17, 2024
Tracked Since
Feb 18, 2026