Record summary

CVE-2024-42501 has a selected CVSS score of 7.2 (high).

Description

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: affected

CVE ListVersion 10.6.0.0: 10.6.0.2 and below to ≤ <=10.6.0.2affected
Version 8.10.0.0: 8.10.0.13 and below to ≤ <=8.10.0.13affected
Version 10.5.0.0: 10.6.0.0 and below to ≤ <=10.6.0.0affected
Version 10.3.0.0: 10.4.0.0 and below to ≤ <=10.4.0.0affected
Version 8.11.0.0: 8.12.0.0 and below to ≤ <=8.12.0.0affected
Version 8.12.0.0: 8.12.0.1 and below to ≤ <=8.12.0.1affected
Version 6.5.4.0: 8.9.0.0 and below to ≤ <=8.9.0.0affected

Default status: unknown

CVE List10.6.0.0 to ≤ 10.6.0.2affected
8.10.0.0 to ≤ 8.10.0.13affected
10.5.0.0 to ≤ 10.6.0.0affected
10.3.0.0 to ≤ 10.4.0.0affected
8.11.0.0 to ≤ 8.12.0.0affected
8.12.0.0 to ≤ 8.12.0.1affected
6.5.4.0 to ≤ 8.9.0.0affected

References

2