nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-47463 CVE-2024-47463
HIGH
Arbitrary File Creation Vulnerability in Instant AOS-8 and AOS-10 leads to Authenticated Remote Command Execution (RCE)
Record summary
CVE-2024-47463 has a selected CVSS score of 7.2 (high).
Description
An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 8, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10Browse Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10Default status: affected | CVE List | AOS-10.4.x.x: 10.4.1.4 and below to ≤ <=10.4.1.4 | affected |
| Instant AOS-8.12.x.x: 8.12.0.2 and below to ≤ <=8.12.0.2 | affected | ||
| Instant AOS-8.10.x.x: 8.10.0.13 and below to ≤ <=8.10.0.13 | affected | ||
Default status: affected | CVE List | 10.4.0.0 to ≤ 10.4.1.4 | affected |
| 10.3.0.0 to < 10.4.0.0 | affected | ||
| 10.5.0.0 to < 10.7.0.0 | affected | ||
Default status: affected | CVE List | 8.12.0.0 to ≤ 8.12.0.2 | affected |
| 8.10.0.0 to ≤ 8.10.0.13 | affected | ||
| 6.4.0.0 to < 6.6.0.0 | affected | ||
| 8.4.0.0 to < 8.10.0.0 | affected | ||
| 8.11.0.0 to < 8.12.0.0 | affected |
References
2support.hpe.com
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&docLocale=en_US