VYPR
Critical severity9.8NVD Advisory· Published Aug 6, 2024· Updated Jun 17, 2026

CVE-2024-42393

CVE-2024-42393

Description

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Affected products

4
  • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
    Range: >=10.3.0.0,<10.4.1.4
  • cpe:2.3:o:hp:instantos:*:*:*:*:*:*:*:*
    Range: >=6.4.0.0,<8.10.0.13
  • Hewlett Packard Enterprise (HPE)/Hpe Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10v5
    Range: Version 8.12.0.0: 8.12.0.1 and below

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.