logo

HPE warns of critical RCE flaws in Aruba Networking access points

ID: e2033ee0-2197-5a9f-a19b-c93ab0b1b619

STIX ID: report--e2033ee0-2197-5a9f-a19b-c93ab0b1b619

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

HPE released security updates for Aruba Instant AOS-8 and AOS-10 to fix two critical unauthenticated RCE vulnerabilities (CVE-2024-42509, CVE-2024-47460) exploitable via the PAPI management protocol on UDP/8211, along with four additional authenticated flaws; affected older AOS/Instant AOS releases should be upgraded to specified patched versions or mitigated by blocking UDP/8211 and restricting management access, and HPE reports no observed active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.