Privileged Command Injection: A Threat to Operating Systems
CVE-2024-31477
Summary
Multiple authenticated command injection vulnerabilities have been identified in the command line interface of Aruba Networks products. Exploiting these vulnerabilities allows an attacker to execute arbitrary commands as a privileged user on the underlying operating system. This severely compromises system integrity and confidentiality, necessitating immediate attention and remediation by system administrators.
Affected Version(s)
Aruba InstantOS and Aruba Access Points running ArubaOS 10 InstantOS or ArubaOS (access points) 10.5.x.x: 10.5.1.0 and below.
Aruba InstantOS and Aruba Access Points running ArubaOS 10 InstantOS or ArubaOS (access points) 10.5.x.x: 10.5.1.0 and below.
Aruba InstantOS and Aruba Access Points running ArubaOS 10 InstantOS or ArubaOS (access points) 10.4.x.x: 10.4.1.0 and below.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved