Description
An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to a remote unauthorized access to files.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10AOS-10.4.x.x: 10.4.1.4 and below – <=10.4.1.4
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10Instant AOS-8.12.x.x: 8.12.0.2 and below – <=8.12.0.2
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10Instant AOS-8.10.x.x: 8.10.0.13 and below – <=8.10.0.13