CVE-2024-31471: Command Injection
There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31471?
CVE-2024-31471 is a critical vulnerability that allows for unauthenticated remote code execution.
How do I fix CVE-2024-31471?
To mitigate CVE-2024-31471, upgrade affected ArubaOS devices to versions 10.4.1.2 or 10.5.1.2 or later, and apply necessary security patches.
What types of software are affected by CVE-2024-31471?
CVE-2024-31471 affects ArubaOS versions between 10.3.0.0 and 10.4.1.1, 10.5.0.0 and 10.5.1.1, and HP InstantOS versions between 6.4.0.0 and 8.6.0.24, as well as between 8.7.0.0 and 8.10.0.11.
What is the potential impact of exploiting CVE-2024-31471?
Exploiting CVE-2024-31471 can allow attackers to execute arbitrary commands remotely on the affected device.
Is CVE-2024-31471 an authenticated or unauthenticated vulnerability?
CVE-2024-31471 is considered an unauthenticated vulnerability, requiring no credentials to exploit.