← Back to browse · API

CVE-2024-31473

Severity
CRITICAL
CVSS
9.8
EPSS
0.01651
Risk score
39.78
CISA KEV
No
PoC
No
Published
2024-05-14
Modified
2025-06-24
First seen
2026-08-07
Aliases
EUVD-2024-29353, GHSA-C6R4-P8CH-2FM8
Products
Hewlett Packard Enterprise (HPE):AOS-8 Instant and AOS-10 AP 10.4.0.0 ≤10.4.1.0, Hewlett Packard Enterprise (HPE):AOS-8 Instant and AOS-10 AP 10.5.0.0 ≤10.5.1.0, Hewlett Packard Enterprise (HPE):AOS-8 Instant and AOS-10 AP 8.10.0.0 ≤8.10.0.10, Hewlett Packard Enterprise (HPE):AOS-8 Instant and AOS-10 AP 8.11.0.0 ≤8.11.2.1, Hewlett Packard Enterprise (HPE):AOS-8 Instant and AOS-10 AP 8.6.0.0 ≤8.6.0.23, Hewlett Packard Enterprise (HPE):Aruba InstantOS and Aruba Access Points running ArubaOS 10 InstantOS or ArubaOS (access points) 10.4.x.x: 10.4.1.0 and below., Hewlett Packard Enterprise (HPE):Aruba InstantOS and Aruba Access Points running ArubaOS 10 InstantOS or ArubaOS (access points) 10.5.x.x: 10.5.1.0 and below., Hewlett Packard Enterprise (HPE):Aruba InstantOS and Aruba Access Points running ArubaOS 10 InstantOS or ArubaOS (access points) 8.10.x.x: 8.10.0.10 and below., Hewlett Packard Enterprise (HPE):Aruba InstantOS and Aruba Access Points running ArubaOS 10 InstantOS or ArubaOS (access points) 8.11.x.x: 8.11.2.1 and below., Hewlett Packard Enterprise (HPE):Aruba InstantOS and Aruba Access Points running ArubaOS 10 InstantOS or ArubaOS (access points) 8.6.x.x: 8.6.0.23 and below.
Sources
euvd EUVD-2024-29353

Description

There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

References