CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-42505

Medium Severity
SVRS
36/100

CVSSv3
NA/10

EPSS
0.00636/1

CVE-2024-42505: Command injection vulnerability in Aruba devices allows unauthenticated remote code execution. Specially crafted packets sent to the PAPI UDP port (8211) can exploit the underlying CLI service. This vulnerability allows attackers to execute arbitrary code with privileged user rights on the operating system.

The SVRS score of 36 indicates a moderate risk, despite the CVSS score being 0. While not immediately critical, CVE-2024-42505 poses a significant threat because successful exploitation grants complete control over affected Aruba devices. Given the "In The Wild" tag, organizations using Aruba equipment should investigate and apply available patches to prevent potential attacks. The ability for unauthenticated remote attackers to gain privileged access makes this a serious security concern.

In The Wild
2024-09-25

2024-09-26

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

HPE Aruba Networking Access Points Vulnerable To Remote Code Execution
Varshini Senapathi2024-09-27
HPE Aruba Networking Access Points Vulnerable To Remote Code Execution | A critical security advisory has been issued by HPE Aruba Networking, warning of multiple vulnerabilities in their Access Points running Instant AOS-8 and AOS-10 software. These vulnerabilities, identified as CVE-2024-42505, CVE-2024-42506, and CVE-2024-42507, could allow unauthenticated remote code execution, posing a significant threat to network security. Affected Products And Software Versions The affected products include […] The post HPE Aruba Networking Access Points Vulnerable
cybersecuritynews.com
rss
forum
news
HPE Aruba Networking fixes critical flaws impacting Access Points - BleepingComputer
2024-09-26
HPE Aruba Networking fixes critical flaws impacting Access Points - BleepingComputer | News Content: HPE Aruba Networking has fixed three critical vulnerabilities in the Command Line Interface (CLI) service of its Aruba Access Points, which could let unauthenticated attackers gain remote code execution on vulnerable devices. The vulnerabilities (CVE-2024-42505, CVE-2024-42506, and CVE-2024-42507) can be exploited by sending specially crafted packets to the PAPI (Aruba’s Access Point management protocol) UDP port (8211) to get privileged access to execute arbitrary code on vulnerable devices. The Hewlett Packard Enterprise (HPE) subsidiary (formerly known as Aruba Networks) confirmed in
cve-2024-42506
cve-2024-42507
cve-2024-42505
ipv4s

Social Media

Actively exploited CVE : CVE-2024-42505
1
0
0

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&docLocale=en_US

CWE Details

CWE IDCWE NameDescription
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence