back to article Patch up – 4 critical bugs in ArubaOS lead to remote code execution

Network admins are being urged to patch a bundle of critical vulnerabilities in ArubaOS that lead to remote code execution as a privileged user. HPE Aruba Networking disclosed ten vulnerabilities this week, four of which are rated "critical" with 9.8 severity ratings. All four of the critical issues are classified as buffer …

  1. that one in the corner Silver badge

    No idea what ArubaOS is[1]

    Which I'll take as a Good Sign, as it indicates that people *are* investigating issues in software other than The Usual Suspects.

    [1] which probably means it actually Does Important Things With Infrastructure instead of just being another boring OS to run yet another tiresome spreadsheet on.

    1. elip

      Re: No idea what ArubaOS is[1]

      It's just another plain old Linux based product...apparently folks at Aruba didn't feel like enabling long-standing protections against common buffer overflows.

    2. Diogenes8080

      Re: No idea what ArubaOS is[1]

      It's Heaving Packhorse - have a look at the logo on your wireless access points and in your patch cabinets. If you see the word "Aruba", start asking questions.

      Original item here for those hitting dud links elsewhere:

      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04640en_us&docLocale=en_US

      Which is little more than the TXT for ARUBA-PSA-2024-004 but slightly easier reading.

  2. Grogan Silver badge

    ... and it's out in the wild, both users reported proof of concept :-)

    (never heard of ArubaOS or their kit... I'm just making a joke)

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like