HPE warns of critical RCE flaws in Aruba Networking access points
ID: e2033ee0-2197-5a9f-a19b-c93ab0b1b619
STIX ID: report--e2033ee0-2197-5a9f-a19b-c93ab0b1b619
Feed Name: Bleeping Computer
Threat Score
HPE released security updates for Aruba Instant AOS-8 and AOS-10 to fix two critical unauthenticated RCE vulnerabilities (CVE-2024-42509, CVE-2024-47460) exploitable via the PAPI management protocol on UDP/8211, along with four additional authenticated flaws; affected older AOS/Instant AOS releases should be upgraded to specified patched versions or mitigated by blocking UDP/8211 and restricting management access, and HPE reports no observed active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
