CVE-2024-42503

HIGH

Aruba OS <= 10.6.0.2 Authenticated OS Command Injection via CLI

Title source: llm
STIX 2.1

Description

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a priviledge user on the underlying operating system.

Scores

CVSS v3 7.2
EPSS 0.0146
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (7)
Hewlett Packard Enterprise (HPE)/Aruba OS Version 10.3.0.0: 10.4.0.0 and below - <=10.4.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS Version 10.5.0.0: 10.6.0.0 and below - <=10.6.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS Version 10.6.0.0: 10.6.0.2 and below - <=10.6.0.2
Hewlett Packard Enterprise (HPE)/Aruba OS Version 6.5.4.0: 8.9.0.0 and below - <=8.9.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS Version 8.10.0.0: 8.10.0.13 and below - <=8.10.0.13
Hewlett Packard Enterprise (HPE)/Aruba OS Version 8.11.0.0: 8.12.0.0 and below - <=8.12.0.0
Hewlett Packard Enterprise (HPE)/Aruba OS Version 8.12.0.0: 8.12.0.1 and below - <=8.12.0.1
Published Sep 17, 2024
Tracked Since Feb 18, 2026