CVE-2024-42503: Arubanetworks Arubaos

High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a priviledge user on the underlying operating system.

Affected products

  • Arubanetworks Arubaos: from 10.3.0.0, before 10.4.0.0 (fixed in 10.4.0.0); from 10.5.0.0, before 10.6.0.0 (fixed in 10.6.0.0); from 10.6.0.0, up to and including 10.6.0.2; from 6.5.4.0, before 6.5.5.0 (fixed in 6.5.5.0); from 8.6.0.0, up to and including 8.10.0.13
  • Hewlett Packard Enterprise HPE Aruba OS

Published 2024-09-17. Last modified 2026-06-17.