CVE-2024-42501

HIGH

Aruba OS <= 10.6.0.2, <= 10.6.0.0, <= 10.4.0.0, <= 8.10.0.13, <= 8.12.0.0, <= 8.12.0.1 - Authenticated Path Traversal

Title source: llm
STIX 2.1

Description

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.

Scores

CVSS v3 7.2
EPSS 0.0114
EPSS Percentile 62.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (7)
Hewlett Packard Enterprise (HPE)/Aruba OS Version 10.3.0.0: 10.4.0.0 and below - <=10.4.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS Version 10.5.0.0: 10.6.0.0 and below - <=10.6.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS Version 10.6.0.0: 10.6.0.2 and below - <=10.6.0.2
Hewlett Packard Enterprise (HPE)/Aruba OS Version 6.5.4.0: 8.9.0.0 and below - <=8.9.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS Version 8.10.0.0: 8.10.0.13 and below - <=8.10.0.13
Hewlett Packard Enterprise (HPE)/Aruba OS Version 8.11.0.0: 8.12.0.0 and below - <=8.12.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS Version 8.12.0.0: 8.12.0.1 and below - <=8.12.0.1
Published Sep 17, 2024
Tracked Since Feb 18, 2026