Aruba Security Updates – 09 January 2025

Aruba has released security updates to fix multiple vulnerabilities affecting Aruba Networking 501 Wireless Client and Aruba CX 10000 Switch Series.

The addressed vulnerabilities could allow the attacker to bypass security restrictions or execute arbitrary commands and gain access to the affected products.

Sample of the addressed vulnerabilities:

HPE Aruba Networking 501 Wireless Client Bridge Authenticated Remote Command Injection Vulnerabilities (CVE-2024-54006, CVE-2024-54007):

  • CVSS: 7.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2024-54006
  • CVE-2024-54007
  • CVE-2024-54010
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Aruba Security Advisory

References