An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos 10 | — | Upgrade Mobility Conductors, Controllers, and Gateways
to one of the following ArubaOS versions (as applicable) to
resolve the vulnerability described in the details section:
- AOS-10.7.x.x: 10.7.0.0 and above
- AOS-10.4.x.x: 10.4.1.5 and above
- AOS-8.12.x.x: 8.12.0.3 and above
- AOS-8.10.x.x: 8.10.0.15 and above | Jan 27, 2025 | Jan 14, 2025 |
| Aruba Aos 8 | — | Upgrade Mobility Conductors, Controllers, and Gateways
to one of the following ArubaOS versions (as applicable) to
resolve the vulnerability described in the details section:
- AOS-10.7.x.x: 10.7.0.0 and above
- AOS-10.4.x.x: 10.4.1.5 and above
- AOS-8.12.x.x: 8.12.0.3 and above
- AOS-8.10.x.x: 8.10.0.15 and above | Jan 21, 2025 | Jan 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub