Record summary

CVE-2024-42509 has a selected CVSS score of 9.8 (critical).

Description

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 8, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: affected

CVE ListAOS-10.4.x.x: 10.4.1.4 and below to ≤ <=10.4.1.4affected
Instant AOS-8.12.x.x: 8.12.0.2 and below to ≤ <=8.12.0.2affected
Instant AOS-8.10.x.x: 8.10.0.13 and below to ≤ <=8.10.0.13affected

Default status: affected

CVE List10.4.0.0 to ≤ 10.4.1.4affected
10.3.0.0 to < 10.4.0.0affected
10.5.0.0 to < 10.7.0.0affected

Default status: affected

CVE List8.12.0.0 to ≤ 8.12.0.2affected
8.10.0.0 to ≤ 8.10.0.13affected
6.4.0.0 to < 6.6.0.0affected
8.4.0.0 to < 8.10.0.0affected
8.11.0.0 to < 8.12.0.0affected

References

2