JoCERT Warns Of HPE Aruba Command Injection Flaws
ID: 83a257fc-7c12-5221-a5d7-e84ed60e8e02
STIX ID: report--83a257fc-7c12-5221-a5d7-e84ed60e8e02
Feed Name: Cyble Blog
Threat Score
This advisory reports two high-severity command injection vulnerabilities (CVE-2024-54006 and CVE-2024-54007) in HPE Aruba 501 Wireless Client Bridge firmware (≤ V2.1.1.0-B0030) that allow authenticated administrators to execute arbitrary commands; both are CVSS 7.2 and a public PoC exists — HPE recommends upgrading to V2.1.2.0-B0033 or later, restricting management access, auditing devices, and monitoring for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
