### [CVE-2024-42394](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42394) ![](https://img.shields.io/static/v1?label=Product&message=HPE%20Aruba%20Networking%20InstantOS%20and%20Aruba%20Access%20Points%20running%20ArubaOS%2010&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=Version%208.10.0.0%3A%208.10.0.12%20and%20below%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=Version%208.12.0.0%3A%208.12.0.1%20and%20below%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=blue) ### Description There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise. ### POC #### Reference - https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04678en_us&docLocale=en_US #### Github No PoCs found on GitHub currently.