Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-42501", "assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0", "state": "PUBLISHED", "assignerShortName": "hpe", "dateReserved": "2024-08-02T17:04:57.631Z", "datePublished": "2024-09-17T17:13:34.722Z", "dateUpdated": "2024-09-18T14:58:56.294Z"}, "containers": {"cna": {"affected": [{"defaultStatus": "affected", "product": "Aruba OS", "vendor": "Hewlett Packard Enterprise (HPE)", "versions": [{"lessThanOrEqual": "<=10.6.0.2", "status": "affected", "version": "Version 10.6.0.0: 10.6.0.2 and below", "versionType": "semver"}, {"lessThanOrEqual": "<=8.10.0.13", "status": "affected", "version": "Version 8.10.0.0: 8.10.0.13 and below", "versionType": "semver"}, {"lessThanOrEqual": "<=10.6.0.0", "status": "affected", "version": "Version 10.5.0.0: 10.6.0.0 and below", "versionType": "semver"}, {"lessThanOrEqual": "<=10.4.0.0", "status": "affected", "version": "Version 10.3.0.0: 10.4.0.0 and below", "versionType": "semver"}, {"lessThanOrEqual": "<=8.12.0.0", "status": "affected", "version": "Version 8.11.0.0: 8.12.0.0 and below", "versionType": "semver"}, {"lessThanOrEqual": "<=8.12.0.1", "status": "affected", "version": "Version 8.12.0.0: 8.12.0.1 and below", "versionType": "semver"}, {"lessThanOrEqual": "<=8.9.0.0", "status": "affected", "version": "Version 6.5.4.0: 8.9.0.0 and below", "versionType": "semver"}]}], "credits": [{"lang": "en", "type": "reporter", "value": "erikdejong"}], "descriptions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "<p>An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants. </p>"}], "value": "An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants."}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.2, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "providerMetadata": {"orgId": "eb103674-0d28-4225-80f8-39fb86215de0", "shortName": "hpe", "dateUpdated": "2024-09-17T17:13:34.722Z"}, "references": [{"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale=en_US"}], "source": {"advisory": "HPESBNW04709", "discovery": "EXTERNAL"}, "title": "Authenticated Path Traversal Vulnerability Leads to a Remote Command Execution (RCE)", "x_generator": {"engine": "Vulnogram 0.2.0"}}, "adp": [{"problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-22", "lang": "en", "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}]}], "affected": [{"vendor": "arubanetworks", "product": "arubaos", "cpes": ["cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "10.6.0.0", "status": "affected", "lessThanOrEqual": "10.6.0.2", "versionType": "semver"}, {"version": "8.10.0.0", "status": "affected", "lessThanOrEqual": "8.10.0.13", "versionType": "semver"}, {"version": "10.5.0.0", "status": "affected", "lessThanOrEqual": "10.6.0.0", "versionType": "semver"}, {"version": "10.3.0.0", "status": "affected", "lessThanOrEqual": "10.4.0.0", "versionType": "semver"}, {"version": "8.11.0.0", "status": "affected", "lessThanOrEqual": "8.12.0.0", "versionType": "semver"}, {"version": "8.12.0.0", "status": "affected", "lessThanOrEqual": "8.12.0.1", "versionType": "semver"}, {"version": "6.5.4.0", "status": "affected", "lessThanOrEqual": "8.9.0.0", "versionType": "semver"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-09-18T14:41:26.544944Z", "id": "CVE-2024-42501", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-18T14:58:56.294Z"}}]}}