Advisories

HPE Aruba 501 Wireless Client Bridge Authenticated Remote Command Injection

Go Back
severity
high
date
Affecting
  • Aruba 501 firmware v2.0.0.0 - v2.1.1.0-B0030

CWE
  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS
8.6
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Hosein Vita
Description
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system. Exploitation evidence was observed by the Shadowserver Foundation on 2024-10-06 UTC.