CVE-2024-42505
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Sep 25, 2024
Updated: Sep 26, 2024
CWE ID 77
Summary
CVE-2024-42505 is a command injection vulnerability affecting Aruba's Access Point management protocol (PAPI). Hackers can exploit this vulnerability by sending specially crafted packets to the PAPI UDP port (8211), leading to unauthenticated remote code execution. Successful exploitation grants the attacker the ability to execute arbitrary code with privileged user access on the underlying operating system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- ArubaOS
Affected Vendors
- Aruba Networks