CVE-2024-42501: Arubanetworks Arubaos

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.

Affected products

  • Arubanetworks Arubaos: from 10.6.0.0, up to and including 10.6.0.2; from 8.10.0.0, up to and including 8.10.0.13; from 10.5.0.0, up to and including 10.6.0.0; from 10.3.0.0, up to and including 10.4.0.0; from 8.11.0.0, up to and including 8.12.0.0; from 8.12.0.0, up to and including 8.12.0.1; …
  • Hewlett Packard Enterprise HPE Aruba OS

Published 2024-09-17. Last modified 2026-06-17.