CVE-2024-42393

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
06/08/2024
Last modified:
12/08/2024

Description

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 10.3.0.0 (including) 10.4.1.4 (excluding)
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 10.5.0.0 (including) 10.6.0.1 (excluding)
cpe:2.3:o:hp:instantos:*:*:*:*:*:*:*:* 6.4.0.0 (including) 8.10.0.13 (excluding)
cpe:2.3:o:hp:instantos:*:*:*:*:*:*:*:* 8.12.0.0 (including) 8.12.0.2 (excluding)