V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-31475
CVE
High

There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management p…

CVSS
8.2
High
EPSS
0.00
p35
Published
2024-01-01
Updated
2024-01-01
Description

There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point.

Tags · CWE
Pre-auth
CWE-463
Affected products
Arubaos 10.3.0.0–10.4.1.1Arubaos 10.5.0.0–10.5.1.1Instantos 6.4.0.0–8.6.0.24Instantos 8.7.0.0–8.10.0.11
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: L
Low (L)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.004 · p35
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
arubaos*Tracked
instantos*Tracked
Source databases
CVE