CVE-2024-33519

A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Configurations

No configuration.

History

21 Nov 2024, 09:17

Type Values Removed Values Added
References () https://csaf.arubanetworks.com/2024/hpe_aruba_networking_-_hpesbnw04673.txt - () https://csaf.arubanetworks.com/2024/hpe_aruba_networking_-_hpesbnw04673.txt -

01 Aug 2024, 13:52

Type Values Removed Values Added
CWE CWE-1321
Summary
  • (es) Una vulnerabilidad en la interfaz de administración basada en web de la puerta de enlace HPE Aruba Networking EdgeConnect SD-WAN podría permitir que un atacante remoto autenticado lleve a cabo un prototipo de ataque de contaminación del lado del servidor. La explotación exitosa de esta vulnerabilidad podría permitir a un atacante ejecutar comandos arbitrarios en el sistema operativo subyacente, lo que podría comprometer completamente el sistema.

24 Jul 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-24 20:15

Updated : 2024-11-21 09:17


NVD link : CVE-2024-33519

Mitre link : CVE-2024-33519

CVE.ORG link : CVE-2024-33519


JSON object : View

Products Affected

No product.

CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')