CVE-2024-42395: Arubanetworks Arubaos

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Affected products

  • Arubanetworks Arubaos: from 10.3.0.0, before 10.4.1.4 (fixed in 10.4.1.4); from 10.5.0.0, before 10.6.0.1 (fixed in 10.6.0.1)
  • HP Instantos: from 6.4.0.0, before 8.10.0.13 (fixed in 8.10.0.13); from 8.12.0.0, before 8.12.0.2 (fixed in 8.12.0.2)

Published 2024-08-06. Last modified 2026-06-17.