HPE ArubaOS
cpe:2.3:o:hpe:arubaos:*:*:*:*:*:*:*
- <= 10.8.0.0
- <= 10.7.2.2
- <= 10.4.1.10
- <= 8.13.1.1
- <= 8.12.0.6
- <= 8.10.0.21
- ~10.6
- ~10.5
- ~10.3
- ~8.12
- ~8.11
- ~8.9
- ~8.8
- ~8.7
- ~8.6
- ~6.5.4
- ~8.7.0.0-2.3.0
- ~8.6.0.4-2.2.x
A command injection vulnerability has been identified in the command line interface (CLI) service accessed by the PAPI protocol of HPE Aruba Networking AOS-8 and AOS-10 Operating Systems. This vulnerability allows authenticated remote attackers to execute arbitrary commands on the underlying operating system. The issue arises from improper input validation, which could be exploited by injecting crafted commands through the CLI interface.
Exploitation of this vulnerability could lead to authenticated remote code execution on the affected system, with the executed commands running as a privileged user.
To address this vulnerability, HPE Aruba Networking recommends upgrading to AOS-10.8.0.1 and above, AOS-10.7.2.3 and above, AOS-10.4.1.11 and above, AOS-8.13.1.2 and above, AOS-8.12.0.7 and above, or AOS-8.10.0.22 and above. For AOS-10 Gateways and AOS-8 Controllers/Mobility Conductors that have reached their End of Maintenance, no patch is available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.