An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.
History

Wed, 18 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks arubaos
Weaknesses CWE-22
CPEs cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks arubaos
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
Description An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.
Title Authenticated Path Traversal Vulnerability Leads to a Remote Command Execution (RCE)
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published: 2024-09-17T17:13:34.722Z

Updated: 2024-09-18T14:58:56.294Z

Reserved: 2024-08-02T17:04:57.631Z

Link: CVE-2024-42501

cve-icon Vulnrichment

Updated: 2024-09-18T14:57:54.443Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-17T18:15:04.337

Modified: 2024-09-20T12:30:51.220

Link: CVE-2024-42501

cve-icon Redhat

No data.