Medium severity6.8NVD Advisory· Published Jul 24, 2024· Updated Jun 17, 2026
CVE-2024-41136
CVE-2024-41136
Description
An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Affected products
2- Hewlett Packard Enterprise (HPE)/HPE Aruba Networking EdgeConnect SD-WANv5Range: ECOS 9.3.x.x: 9.3.3.0 and below
Patches
Vulnerability mechanics
References
1- csaf.arubanetworks.com/2024/hpe_aruba_networking_-_hpesbnw04673.txtnvdVendor Advisory
News mentions
0No linked articles in our index yet.