PT-2024-2100 · Aruba · Arubaos

Published

2024-03-05

·

Updated

2024-10-29

·

CVE-2024-25614

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions ArubaOS (affected versions not specified)
Description The issue is related to an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to denial-of-service conditions and impact the integrity of the controller. The vulnerability is also associated with insufficient access control in the CLI interface, allowing a remote attacker to access and delete arbitrary files, potentially causing a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-01996
CVE-2024-25614

Affected Products

Arubaos