nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-42507 CVE-2024-42507
CRITICAL
Unauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI Protocol
Record summary
CVE-2024-42507 has a selected CVSS score of 9.8 (critical).
Description
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version 10.5.0.0: 10.6.0.2 and below to ≤ <=10.6.0.2 | affected |
| Version 10.0.0.0: 10.4.1.13 and below to ≤ <=10.4.1.13 | affected | ||
| Version 6.4.0.0: 8.10.0.13 and below to ≤ <=8.10.0.13 | affected | ||
| Version 8.11.0.0: 8.12.0.1 and below to ≤ <=8.12.0.1 | affected | ||
Default status: unknown | CVE List | 10.5.0.0 to ≤ 10.6.0.2 | affected |
| 10.0.0.0 to ≤ 10.4.1.13 | affected | ||
| 6.4.0.0 to ≤ 8.10.0.13 | affected | ||
| 8.11.0.0 to ≤ 8.12.0.1 | affected |
References
2support.hpe.com
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&docLocale=en_US