CVE-2024-42502: Arubanetworks Arubaos

High severity, CVSS 7.2. EPSS: 1.8% chance of exploitation in the next 30 days.

Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underlying operating system.

Affected products

  • Arubanetworks Arubaos: from 10.6.0.0, up to and including 10.6.0.2; from 8.10.0.0, up to and including 8.10.0.13; from 10.5.0.0, up to and including 10.6.0.0; from 10.3.0.0, up to and including 10.4.0.0; from 8.11.0.0, up to and including 8.12.0.0; from 8.12.0.0, up to and including 8.12.0.1; …
  • Hewlett Packard Enterprise HPE Aruba OS

Published 2024-09-17. Last modified 2026-06-17.