Home

Description

There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point

PUBLISHED Reserved 2024-04-03 | Published 2024-05-14 | Updated 2025-06-24 | Assigner hpe




HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Product status

Default status
unaffected

10.5.0.0 (semver)
affected

10.4.0.0 (semver)
affected

8.11.0.0 (semver)
affected

8.10.0.0 (semver)
affected

8.6.0.0 (semver)
affected

Credits

Chancen reporter

References

www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt

support.hpe.com/...y?docId=hpesbnw04647en_us&docLocale=en_US

cve.org (CVE-2024-31474)

nvd.nist.gov (CVE-2024-31474)

Download JSON