7.2

CVE-2024-42503

Authenticated command execution vulnerability exist in the  ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a priviledge user on the underlying operating system.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Vendorarubanetworks
Product arubaos
Default Statusunknown
Version < 10.4.0.0
Version 10.3.0.0
Status affected
Version < 10.6.0.0
Version 10.5.0.0
Status affected
Version <= 10.6.0.2
Version 10.6.0.0
Status affected
Version < 6.5.5.0
Version 6.5.4.0
Status affected
Version <= 8.10.0.13
Version 8.6.0.0
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.45% 0.625
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
security-alert@hpe.com 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.