HPE ArubaOS
cpe:2.3:o:hp:arubaos:*:*:*:*:*:*:*, +2 more
- >= 10.8.0.0, <= 10.8.0.0
- >= 10.7.0.0, <= 10.7.2.2
- >= 10.4.0.0, <= 10.4.1.10
- ~10.6
- ~10.5
- ~10.3
A command injection vulnerability has been identified in the command line interface of HPE Aruba Access Points running AOS-10.7.x.x and above. This vulnerability allows authenticated remote attackers to execute arbitrary commands on the underlying operating system. Access Points on the AOS-10.4 branch and AOS-8 Instant software are not affected.
Exploitation of this vulnerability could lead to unauthorized execution of commands on the affected Access Points' operating system, potentially allowing for further exploitation or manipulation of the device.
To address this vulnerability, it is recommended to upgrade to AOS-10 AP version 10.8.0.1 and above or to version 10.7.2.3 and above. For more information, visit the HPE Networking Support Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.