Three critical vulnerabilities could lead to arbitrary code execution in multiple series of Aruba Access Points
Summary
Three critical vulnerabilities could lead to arbitrary code execution in multiple series of Aruba Access Points
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Hewlett Packard Enterprise (HPE) Aruba Networking has issued an advisory that addresses 3 vulnerabilities that affect Aruba Access Points (APs) product lines that use Instant AOS (ArubaOS). AOS is a distributed network operating system working with Aruba Central that controls APs and optional gateways.
Three critical command injection vulnerabilities that have CVSSv3 scores of 9.8 could be exploited by an unauthenticated, remote attacker via a specially crafted packet to achieve remote code execution (RCE). Successful exploitation could lead to the ability to execute arbitrary code as a privileged user on the underlying operating system.
Remediation advice
Affected organisations are encouraged to review the HPE Security Advisory HPESBNW04712 rev.1 - HPE Aruba Networking Access Points Multiple Vulnerabilities and apply any relevant updates or workarounds.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 26 September 2024 4:40 pm