CVE-2020-24635: OS Command Injection
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.5 and below; Aruba Instant 8.7.x: 8.7.0.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-24635.
What is the severity of CVE-2020-24635?
The severity of CVE-2020-24635 is critical with a CVSS score of 7.2.
Which products are affected by CVE-2020-24635?
Aruba Instant Access Point (IAP) products in versions: Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.5 and below.
What is the recommended version to fix CVE-2020-24635?
To fix CVE-2020-24635, it is recommended to upgrade to Aruba Instant versions 6.5.4.18, 8.3.0.14, 8.5.0.11, or 8.6.0.6 or above.
Where can I find more information about CVE-2020-24635?
More information about CVE-2020-24635 can be found in the references provided: [Siemens Advisory](https://cert-portal.siemens.com/productcert/pdf/ssa-723417.pdf) and [Aruba Networks Advisory](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2021-007.txt).