Hewlett Packard Enterprise (HPE) has released updates for Instant AOS-8 and AOS-10 to fix two critical vulnerabilities in Aruba Networking Access Points.

The vulnerabilities, tracked as CVE-2024-42509 (9.8/10) and CVE-2024-47460 (9.0/10), could allow a remote attacker to perform unauthorized command injection by sending specially crafted packets to the Aruba Access Point Management Protocol (PAPI) over UDP port 8211 .
Both vulnerabilities are located in the command line interface (CLI) service, which is accessed via the PAPI protocol.
See also: CISA: Added Palo Alto Networks vulnerability to the KEV List
The HPE update fixes four other security vulnerabilities: CVE-2024-47461 (7.2/10), CVE-2024-47462 and CVE-2024-47463 (7.2/10), and CVE-2024-47464 (6.8/10). The first three vulnerabilities could lead to remote command execution on the underlying operating system, while the last one allows access to unauthorized files via path traversal.
All six vulnerabilities affect versions AOS-10.4.xx: 10.4.1.4 and earlier, Instant AOS-8.12.xx: 8.12.0.2 and earlier, and Instant AOS-8.10.xx: 8.10.0.13 and earlier.
Additionally, according to HPE, the vulnerabilities affect several other versions that are no longer supported by the company, so there will be no security updates for them.
See also: CISA warns of vulnerabilities in PTZOptics cameras
To address vulnerabilities in Aruba Networking Access Points, HPE recommends updating devices to the following software:
- AOS-10.7.xx: Update to version 10.7.0.0 and later.
- AOS-10.4.xx: Update to version 10.4.1.5 or later.
- Instant AOS-8.12.xx: Update to version 8.12.0.3 or later.
- Instant AOS-8.10.xx: Update to version 8.10.0.14 or later.
HPE has also provided other solutions to help in cases where software updates cannot be installed immediately:
- For the two critical flaws, the recommended solution is to restrict/block access to UDP port 8211.
- For other issues, it is recommended to restrict access to the CLI and web-based management interfaces.

According to HPE, no active exploitation of the vulnerabilities in Aruba Networking Access Points has been observed, but the implementation of security updates and other protection measures is considered necessary.
See also: Okta Verify Agent Vulnerability Allows Password Theft
Additionally, organizations should incorporate regular assessments security and audits to identify potential vulnerabilities and should implement necessary measures to address them. A proactive approach to network security is vital in today's evolving threat landscape.
In addition to patching vulnerabilities, it is important for organizations to also establish control policies access. This includes limiting unauthorized access to critical network devices and implementing strong authentication mechanisms, such as multi-factor authentication. It is important for organizations to regularly review and update these policies to ensure they are effective against emerging threats.
Source: www.bleepingcomputer.com
