« Volver al listado

CVE-2024-42393

Estado: AnalizadaCrítica (9.8)—

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-42393",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-42393",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-06T19:13:40.644282Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-alert@hpe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "Hewlett Packard Enterprise (HPE)",
          "product": "Hpe Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10",
          "versions": [
            {
              "status": "affected",
              "version": "Version 8.12.0.0: 8.12.0.1 and below",
              "versionType": "semver",
              "lessThanOrEqual": "<=8.12.0.1"
            },
            {
              "status": "affected",
              "version": "Version 8.10.0.0: 8.10.0.12 and below",
              "versionType": "semver",
              "lessThanOrEqual": "<=8.10.0.12"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:instant:*:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "instant",
          "versions": [
            {
              "status": "affected",
              "version": "8.10.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.10.0.12"
            },
            {
              "status": "affected",
              "version": "8.12.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.12.0.1"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-08-06T19:15:56.640",
  "references": [
    {
      "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise."
    },
    {
      "lang": "es",
      "value": "Existen vulnerabilidades en el Soft AP Daemon Service que podrían permitir que un actor de amenazas ejecute un ataque RCE no autenticado. Una explotación exitosa podría permitir a un atacante ejecutar comandos arbitrarios en el sistema operativo subyacente, lo que podría comprometer completamente el sistema."
    }
  ],
  "lastModified": "2026-06-17T07:49:23.007",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "342197F7-9F17-4EED-9EEF-A5B1BB688234",
              "versionEndExcluding": "10.4.1.4",
              "versionStartIncluding": "10.3.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A600ADA-377E-400A-A409-C1D4CEE86286",
              "versionEndExcluding": "10.6.0.1",
              "versionStartIncluding": "10.5.0.0"
            },
            {
              "criteria": "cpe:2.3:o:hp:instantos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "661E77B0-1019-42EE-9DEE-9120E1E6CA81",
              "versionEndExcluding": "8.10.0.13",
              "versionStartIncluding": "6.4.0.0"
            },
            {
              "criteria": "cpe:2.3:o:hp:instantos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD98FE10-885C-4631-B68B-34E8CC227A59",
              "versionEndExcluding": "8.12.0.2",
              "versionStartIncluding": "8.12.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}