CVE-2024-42505
CVE-2024-42505: Command injection vulnerability in Aruba devices allows unauthenticated remote code execution. Specially crafted packets sent to the PAPI UDP port (8211) can exploit the underlying CLI service. This vulnerability allows attackers to execute arbitrary code with privileged user rights on the operating system.
The SVRS score of 36 indicates a moderate risk, despite the CVSS score being 0. While not immediately critical, CVE-2024-42505 poses a significant threat because successful exploitation grants complete control over affected Aruba devices. Given the "In The Wild" tag, organizations using Aruba equipment should investigate and apply available patches to prevent potential attacks. The ability for unauthenticated remote attackers to gain privileged access makes this a serious security concern.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.