CVE-2024-42502: Authenticated Remote Command Execution (RCE) Vulnerability in the AOS Command Line Interface
Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42502?
The severity of CVE-2024-42502 is considered high due to the potential for authenticated command injection leading to unauthorized execution of shell commands.
How do I fix CVE-2024-42502?
To fix CVE-2024-42502, update your ArubaOS to the latest patched version provided by Aruba.
What type of vulnerability is CVE-2024-42502?
CVE-2024-42502 is an authenticated command injection vulnerability in the ArubaOS command line interface.
Who is affected by CVE-2024-42502?
Organizations using affected versions of ArubaOS are vulnerable to CVE-2024-42502 if they allow authenticated users access to the command line interface.
What can happen if CVE-2024-42502 is exploited?
If CVE-2024-42502 is exploited, an attacker can inject and execute malicious shell commands on the underlying operating system.