logo

Security Upgrades Available for 3 HPE Aruba Networking Bugs

ID: c804503c-3333-59c2-a991-3d53fca097b0

STIX ID: report--c804503c-3333-59c2-a991-3d53fca097b0

Feed Name: Dark Reading

Threat Score
60/100

Date Published: 2024-09-26

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Hewlett Packard Enterprise (Aruba Networking) disclosed and fixed three critical remote code execution vulnerabilities in the CLI service of Aruba access points (CVE-2024-42505 / CVE-2024-42506 / CVE-2024-42507) that can be triggered by sending packets to the AP management UDP port. Affected Instant AOS-8 and AOS-10 firmware versions are enumerated; HPE provides workarounds for some 8.x/AOS-10 devices but strongly recommends applying the supplied updates. HPE reports no known exploitation in the wild and no public exploit code at the time of the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.