CVE-2024-47464 is an authenticated Path Traversal vulnerability affecting Instant AOS-8 and AOS-10. This flaw allows a highly privileged attacker to copy arbitrary files to a user-readable location via the command line interface. With a CVSS score of 6.8 (Medium), successful exploitation could lead to unauthorized remote access to files. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Despite limited community discussion, media coverage indicates awareness of this and related Aruba vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | HPE Aruba Networking Access Points, Instant AOS-8, And AOS-10 | >= AOS-10.4.x.x: 10.4.1.4 and below, <= <=10.4.1.4, >= Instant AOS-8.10.x.x: 8.10.0.13 and below, <= <=8.10.0.13, >= Instant AOS-8.12.x.x: 8.12.0.2 and below, <= <=8.12.0.2CNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.