HPE has addressed a critical remote code execution (RCE) vulnerability affecting its ArubaOS-CX network switches. The vulnerability, tracked as CVE-2024-47430, resides in the web-based management interface of the devices. It allows an unauthenticated attacker to execute arbitrary commands with administrative privileges on the operating system.
This flaw is particularly severe as it can be exploited remotely without user interaction. HPE has released firmware updates to mitigate the risk and recommends that administrators apply these patches immediately. The security advisory covers multiple versions of the ArubaOS-CX software across various switch models.
Organizations that cannot immediately apply the updates are encouraged to restrict access to the web management interface or place it behind a dedicated management network to reduce the attack surface. This fix follows a series of recent updates from HPE aimed at hardening their enterprise networking products against similar injection attacks.
Top comments (0)