Hewlett Packard Enterprise (HPE) has released urgent security patches to resolve several vulnerabilities in Aruba Networking Access Point products, including two severe command injection flaws. Known as CVE-2024-42509 and CVE-2024-47460, these vulnerabilities impact devices running the Instant AOS-8 and AOS-10 software, specifically versions 10.4.1.4 and earlier, 8.12.0.2 and earlier, and 8.10.0.13 and earlier. These high-severity issues, rated with CVSS scores of 9.8 and 9.0, enable unauthenticated attackers to execute commands remotely by sending specially crafted packets to the PAPI UDP port (8211). To protect against these critical vulnerabilities, HPE advises enabling cluster security on Instant AOS-8 devices via the cluster-security command. For AOS-10 users, blocking UDP port 8211 from untrusted networks is recommended. Additionally, HPE has resolved four other vulnerabilities: an authenticated remote code execution issue (CVE-2024-47461), a vulnerability that could lead to arbitrary file creation (CVE-2024-47462 and CVE-2024-47463), and a path traversal flaw (CVE-2024-47464), which may result in unauthorized access or code execution. As a security measure, HPE recommends placing management interfaces on isolated VLANs and applying firewall rules to limit access. Although there is no evidence that these vulnerabilities have been exploited in the wild, experts caution that unpatched systems could become prime targets for future attacks.
Charter Communications has confirmed a cybersecurity incident impacting millions of customers following a breach allegedly conducted by the ShinyHunters extortion gang. According t...
A critical Remote Code Execution (RCE) vulnerability has been identified in Samba, the widely used open-source SMB/CIFS file-sharing software for Linux and Unix systems. The flaw c...
A sophisticated cyber-espionage campaign linked to the Iran-aligned threat group Seedworm has targeted at least nine organizations across multiple countries during early 2026. The ...