vulnerability
Aruba AOS-10: CVE-2024-31475: Unauthenticated Arbitrary File Deletion in Central Communications Service Accessed by the PAPI Protocol
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:P/A:C) | May 14, 2024 | Jan 14, 2025 | Jul 2, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:C)
Published
May 14, 2024
Added
Jan 14, 2025
Modified
Jul 2, 2025
Description
There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point.
Solution
aruba-aos-10-cve-2024-31475
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.