CVE-2024-31482OS Command Injection in Arubaos

Severity
7.5HIGHNVD
CNA5.3
EPSS
0.2%
top 52.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 15

Description

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected Access Point.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDhp/instantos6.4.0.08.6.0.24+1
NVDarubanetworks/arubaos10.3.0.010.4.1.1+1

🔴Vulnerability Details

2
GHSA
GHSA-pjp4-f857-pw2v: An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol2024-05-15
CVEList
CVE-2024-31482: An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol2024-05-14
CVE-2024-31482 — OS Command Injection in Arubaos | cvebase