An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 18 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arubanetworks
Arubanetworks arubaos |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Arubanetworks
Arubanetworks arubaos |
|
| Metrics |
ssvc
|
Tue, 17 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants. | |
| Title | Authenticated Path Traversal Vulnerability Leads to a Remote Command Execution (RCE) | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published: 2024-09-17T17:13:34.722Z
Updated: 2024-09-18T14:58:56.294Z
Reserved: 2024-08-02T17:04:57.631Z
Link: CVE-2024-42501
Updated: 2024-09-18T14:57:54.443Z
Status : Awaiting Analysis
Published: 2024-09-17T18:15:04.337
Modified: 2024-09-20T12:30:51.220
Link: CVE-2024-42501
No data.