An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos 10 | — | Upgrade Mobility Conductors, Mobility Controllers and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section:
- AOS-10.7.x.x: 10.7.0.0 and above
- AOS-10.6.x.x: 10.6.0.3 and above
- AOS-8.12.x.x: 8.12.0.2 and above
- AOS-8.10.x.x: 8.10.0.14 and above
Note: AOS-10.4.x.x is not affected by any of the vulnerabilities above. | Jan 14, 2025 | Sep 17, 2024 |
| Aruba Aos 8 | — | Upgrade Mobility Conductors, Mobility Controllers and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section:
- AOS-10.7.x.x: 10.7.0.0 and above
- AOS-10.6.x.x: 10.6.0.3 and above
- AOS-8.12.x.x: 8.12.0.2 and above
- AOS-8.10.x.x: 8.10.0.14 and above
Note: AOS-10.4.x.x is not affected by any of the vulnerabilities above. | Jan 14, 2025 | Sep 17, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub