nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-42503 CVE-2024-42503
HIGH
Authenticated Remote Command Execution (RCE) Vulnerability in the Lua Package Within the AOS Command Line Interface (CLI)
Record summary
CVE-2024-42503 has a selected CVSS score of 7.2 (high).
Description
Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a priviledge user on the underlying operating system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version 10.6.0.0: 10.6.0.2 and below to ≤ <=10.6.0.2 | affected |
| Version 8.10.0.0: 8.10.0.13 and below to ≤ <=8.10.0.13 | affected | ||
| Version 10.5.0.0: 10.6.0.0 and below to ≤ <=10.6.0.0 | affected | ||
| Version 10.3.0.0: 10.4.0.0 and below to ≤ <=10.4.0.0 | affected | ||
| Version 8.11.0.0: 8.12.0.0 and below to ≤ <=8.12.0.0 | affected | ||
| Version 8.12.0.0: 8.12.0.1 and below to ≤ <=8.12.0.1 | affected | ||
| Version 6.5.4.0: 8.9.0.0 and below to ≤ <=8.9.0.0 | affected | ||
Default status: unknown | CVE List | 10.3.0.0 to < 10.4.0.0 | affected |
| 10.5.0.0 to < 10.6.0.0 | affected | ||
| 10.6.0.0 to ≤ 10.6.0.2 | affected | ||
| 6.5.4.0 to < 6.5.5.0 | affected | ||
| 8.6.0.0 to ≤ 8.10.0.13 | affected |
References
2support.hpe.com
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale=en_US