CVE-2024-42501

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.
Configurations

No configuration.

History

18 Sep 2024, 15:35

Type Values Removed Values Added
CWE CWE-22
Summary
  • (es) Existe una vulnerabilidad de Path Traversal autenticado en ArubaOS. La explotación exitosa de esta vulnerabilidad permite a un atacante instalar paquetes no firmados en el sistema operativo subyacente, lo que le permite al actor de la amenaza ejecutar código arbitrario o instalar implantes.

17 Sep 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-17 18:15

Updated : 2024-09-20 12:30


NVD link : CVE-2024-42501

Mitre link : CVE-2024-42501

CVE.ORG link : CVE-2024-42501


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')