Imechapishwa: Apr 26, 2025 23:28
Advisory No: TZCERT-SA-25-0090
Source: HP
Software Affected: HPE Telco Unified OSS Console, HPE Telco Service Orchestrator
Three critical vulnerabilities are affecting HPE Telco Unified OSS Console and HPE Telco Service Orchestrator. Exploitation of these vulnerabilities may allow an attacker to execute remote code.
HPE Aruba Networking Access Points are affected by vulnerabilities tracked as CVE-2025-24813, CVE-2025-29774, and CVE-2025-29775 with CVSS scores of 9.8, 9.1, and 9.1, respectively. The vulnerabilities results from original implementation of partial PUT used a temporary file based on the user provided file name and path with the path separator replaced by ".”, Improper Verification of Cryptographic Signature through the SignedInfo references and Improper Verification of Cryptographic Signature due to the manipulation of the DigestValue element within the XML structure. The vulnerabilities allow remote Server-Side Request Forgery (SSRF), Local Denial of Service (DoS), Remote Denial of Service (DoS), Local Buffer Overflow, Remote Buffer Overflow, Local Input Validation, and Remote Code Execution on the affected device.
Successful exploitation of these vulnerabilities may allow the attackers to take control of the affected system.
HP has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.
A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.