CVE-2024-42509

CRITICAL

Aruba CLI Service - Command Injection

Title source: llm
STIX 2.1

Description

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

Scores

CVSS v3 9.8
EPSS 0.0198
EPSS Percentile 77.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-77
Status published
Products (3)
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10 AOS-10.4.x.x: 10.4.1.4 and below - <=10.4.1.4
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10 Instant AOS-8.10.x.x: 8.10.0.13 and below - <=8.10.0.13
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10 Instant AOS-8.12.x.x: 8.12.0.2 and below - <=8.12.0.2
Published Nov 05, 2024
Tracked Since Feb 18, 2026