vulnerability

Aruba AOS-CX: CVE-2024-12087: Multiple Vulnerabilities in Rsync Daemon allow for Remote Code Execution, Directory Traversal, and Sensitive Information Disclosure

Severity
6
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:N)
Published
Nov 18, 2025
Added
Nov 28, 2025
Modified
Nov 28, 2025

Description

Rsync, a versatile file-synchronizing tool, contains six vulnerabilities present within versions 3.3.0 and below. Rsync can be used to sync files between remote and local computers, as well as storage devices. The discovered vulnerabilities include heap-buffer overflow, information leak, file leak, external directory file-write, safe-links bypass, and symbolic-link race condition.

Solution

aruba-aos-cx-cve-2024-12087
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.