Aruba AP CLI Arbitrary File Deletion via PAPI
CVE-2024-31474 Published on May 14, 2024

There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point

NVD

Vulnerability Analysis

CVE-2024-31474 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and a high impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
LOW
Availability Impact:
HIGH

Weakness Type

Deletion of Data Structure Sentinel

The accidental deletion of a data-structure sentinel can cause serious programming logic problems. Often times data-structure sentinels are used to mark structure of the data structure. A common example of this is the null character at the end of strings. Another common example is linked lists which may contain a sentinel to mark the end of the list. It is dangerous to allow this type of control data to be easily accessible. Therefore, it is important to protect from the deletion or modification outside of some wrapper interface which provides safety.


Products Associated with CVE-2024-31474

stack.watch emails you whenever new vulnerabilities are published in Aruba Networks Arubaos or HP Instantos. Just hit a watch button to start following.

 
 

Affected Versions

Hewlett Packard Enterprise (HPE) AOS-8 Instant and AOS-10 AP: arubanetworks arubaos: arubanetworks arubaos: arubanetworks instant: arubanetworks instant: arubanetworks instant: arubanetworks arubaos: arubanetworks instant: arubanetworks instant: arubanetworks instant: arubanetworks instant: arubanetworks instant: arubanetworks instant: arubanetworks instant:

Exploit Probability

EPSS
1.58%
Percentile
81.38%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.