Arbitrary File Deletion Vulnerability in ArubaOS CLI Could Lead to Denial-of-Service Conditions
CVE-2024-25614

9.1CRITICAL

Key Information:

Vendor

HP

Vendor
CVE Published:
5 March 2024

What is CVE-2024-25614?

An arbitrary file deletion vulnerability exists within the Command Line Interface (CLI) of ArubaOS. When exploited, this vulnerability allows an attacker to delete any file on the underlying operating system, which can result in disruption of services and compromise the entire integrity of the network controller. Such an event can lead to severe operational challenges, including potential denial-of-service conditions.

Affected Version(s)

ArubaOS Wi-Fi Controllers and Campus/Remote Access Points ArubaOS 10.5.x.x: 10.5.0.1 and below

ArubaOS Wi-Fi Controllers and Campus/Remote Access Points ArubaOS 10.5.x.x: 10.5.0.1 and below

ArubaOS Wi-Fi Controllers and Campus/Remote Access Points ArubaOS 10.4.x.x: 10.4.0.3 and below

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Erik De Jong (bugcrowd.com/erikdejong)
.