nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-42501 CVE-2024-42501
HIGH
Authenticated Path Traversal Vulnerability Leads to a Remote Command Execution (RCE)
Record summary
CVE-2024-42501 has a selected CVSS score of 7.2 (high).
Description
An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version 10.6.0.0: 10.6.0.2 and below to ≤ <=10.6.0.2 | affected |
| Version 8.10.0.0: 8.10.0.13 and below to ≤ <=8.10.0.13 | affected | ||
| Version 10.5.0.0: 10.6.0.0 and below to ≤ <=10.6.0.0 | affected | ||
| Version 10.3.0.0: 10.4.0.0 and below to ≤ <=10.4.0.0 | affected | ||
| Version 8.11.0.0: 8.12.0.0 and below to ≤ <=8.12.0.0 | affected | ||
| Version 8.12.0.0: 8.12.0.1 and below to ≤ <=8.12.0.1 | affected | ||
| Version 6.5.4.0: 8.9.0.0 and below to ≤ <=8.9.0.0 | affected | ||
Default status: unknown | CVE List | 10.6.0.0 to ≤ 10.6.0.2 | affected |
| 8.10.0.0 to ≤ 8.10.0.13 | affected | ||
| 10.5.0.0 to ≤ 10.6.0.0 | affected | ||
| 10.3.0.0 to ≤ 10.4.0.0 | affected | ||
| 8.11.0.0 to ≤ 8.12.0.0 | affected | ||
| 8.12.0.0 to ≤ 8.12.0.1 | affected | ||
| 6.5.4.0 to ≤ 8.9.0.0 | affected |
References
2support.hpe.com
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale=en_US