Show plain JSON{"dataType": "CVE_RECORD", "containers": {"adp": [{"title": "CISA ADP Vulnrichment", "metrics": [{"other": {"type": "ssvc", "content": {"id": "CVE-2024-47463", "role": "CISA Coordinator", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "version": "2.0.3", "timestamp": "2024-11-06T15:15:20.421349Z"}}}], "affected": [{"cpes": ["cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*"], "vendor": "arubanetworks", "product": "arubaos", "versions": [{"status": "affected", "version": "10.4.0.0", "versionType": "semver", "lessThanOrEqual": "10.4.1.4"}, {"status": "affected", "version": "10.3.0.0", "lessThan": "10.4.0.0", "versionType": "semver"}, {"status": "affected", "version": "10.5.0.0", "lessThan": "10.7.0.0", "versionType": "semver"}], "defaultStatus": "affected"}, {"cpes": ["cpe:2.3:o:arubanetworks:instant:*:*:*:*:*:*:*:*"], "vendor": "arubanetworks", "product": "instant", "versions": [{"status": "affected", "version": "8.12.0.0", "versionType": "semver", "lessThanOrEqual": "8.12.0.2"}, {"status": "affected", "version": "8.10.0.0", "versionType": "semver", "lessThanOrEqual": "8.10.0.13"}, {"status": "affected", "version": "6.4.0.0", "lessThan": "6.6.0.0", "versionType": "semver"}, {"status": "affected", "version": "8.4.0.0", "lessThan": "8.10.0.0", "versionType": "semver"}, {"status": "affected", "version": "8.11.0.0", "lessThan": "8.12.0.0", "versionType": "semver"}], "defaultStatus": "affected"}], "problemTypes": [{"descriptions": [{"lang": "en", "type": "CWE", "description": "CWE-noinfo Not enough information"}]}], "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-11-06T15:41:18.642Z"}}], "cna": {"title": "Arbitrary File Creation Vulnerability in Instant AOS-8 and AOS-10 leads to Authenticated Remote Command Execution (RCE)", "source": {"advisory": "HPESBNW04722", "discovery": "EXTERNAL"}, "credits": [{"lang": "en", "type": "reporter", "value": "zzcentury from Ubisectech Sirius Team (https://www.ubisectech.com/)"}], "metrics": [{"format": "CVSS", "cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.2, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "HIGH", "confidentialityImpact": "HIGH"}, "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "affected": [{"vendor": "Hewlett Packard Enterprise (HPE)", "product": "HPE Aruba Networking Access Points, Instant AOS-8, and AOS-10", "versions": [{"status": "affected", "version": "AOS-10.4.x.x: 10.4.1.4 and below", "versionType": "semver", "lessThanOrEqual": "<=10.4.1.4"}, {"status": "affected", "version": "Instant AOS-8.12.x.x: 8.12.0.2 and below", "versionType": "semver", "lessThanOrEqual": "<=8.12.0.2"}, {"status": "affected", "version": "Instant AOS-8.10.x.x: 8.10.0.13 and below", "versionType": "semver", "lessThanOrEqual": "<=8.10.0.13"}], "defaultStatus": "affected"}], "datePublic": "2024-11-05T17:00:00.000Z", "references": [{"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&docLocale=en_US"}], "x_generator": {"engine": "Vulnogram 0.2.0"}, "descriptions": [{"lang": "en", "value": "An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.", "supportingMedia": [{"type": "text/html", "value": "<div><div>An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.</div></div>", "base64": false}]}], "providerMetadata": {"orgId": "eb103674-0d28-4225-80f8-39fb86215de0", "shortName": "hpe", "dateUpdated": "2024-11-05T22:59:04.966Z"}}}, "cveMetadata": {"cveId": "CVE-2024-47463", "state": "PUBLISHED", "dateUpdated": "2024-11-09T04:55:52.279Z", "dateReserved": "2024-09-24T18:13:23.209Z", "assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0", "datePublished": "2024-11-05T22:59:04.966Z", "assignerShortName": "hpe"}, "dataVersion": "5.1"}