Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in Aruba EdgeConnect

Multiple vulnerabilities in Aruba EdgeConnect allow for privilege escalation, denial of service, information disclosure, file manipulation, cross-site scripting, security bypass, and arbitrary code execution.

CVE search metadata

CVE search record: CVE-2024-39499. Severity: high. CVSS: 7.1. EPSS: 0.30%. KEV: no. Product: Aruba EdgeConnect. Brief: Multiple Vulnerabilities in Aruba EdgeConnect. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aruba-edgeconnect/

CVE search record: CVE-2024-39500. Severity: high. CVSS: 7.8. EPSS: 0.22%. KEV: no. Product: Aruba EdgeConnect. Brief: Multiple Vulnerabilities in Aruba EdgeConnect. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aruba-edgeconnect/

CVE search record: CVE-2024-39501. KEV: no. Product: Aruba EdgeConnect. Brief: Multiple Vulnerabilities in Aruba EdgeConnect. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aruba-edgeconnect/

CVE search record: CVE-2024-39502. Severity: high. CVSS: 7.8. EPSS: 0.31%. KEV: no. Product: Aruba EdgeConnect. Brief: Multiple Vulnerabilities in Aruba EdgeConnect. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aruba-edgeconnect/

CVE search record: CVE-2024-39503. Severity: high. CVSS: 7.8. EPSS: 0.22%. KEV: no. Product: Aruba EdgeConnect. Brief: Multiple Vulnerabilities in Aruba EdgeConnect. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aruba-edgeconnect/

HPE has released a security advisory addressing multiple vulnerabilities in Aruba EdgeConnect (CVE-2024-39499, CVE-2024-39500, CVE-2024-39501, CVE-2024-39502, CVE-2024-39503). These vulnerabilities collectively expose the network appliance to significant risks, including unauthenticated or authenticated arbitrary code execution, privilege escalation, and sensitive information disclosure. Attackers may also leverage these flaws to conduct denial-of-service (DoS) attacks, manipulate system files, perform cross-site scripting (XSS), or bypass existing security controls. Due to the critical nature of these vulnerabilities in network infrastructure, organizations deploying Aruba EdgeConnect should prioritize the assessment of their exposure and apply the vendor-provided patches immediately to mitigate the risk of unauthorized remote control or service disruption.

Impact

Successful exploitation of these vulnerabilities could result in full system compromise of the Aruba EdgeConnect appliance, leading to unauthorized access to sensitive network traffic, disruption of network services, or persistent unauthorized access to the environment. The vulnerabilities affect the core functionality of the device, which is typically used for Wide Area Network (WAN) optimization and Software-Defined WAN (SD-WAN) routing, making it a high-value target for lateral movement and traffic interception.

Recommendation

  • Identify all instances of Aruba EdgeConnect within the network environment.
  • Apply the latest security patches provided by HPE for Aruba EdgeConnect immediately to address CVE-2024-39499, CVE-2024-39500, CVE-2024-39501, CVE-2024-39502, and CVE-2024-39503.
  • Review network appliance logs for abnormal administrative activity, unauthorized file modifications, or anomalous HTTP requests targeting management interfaces.

Immediate actions

Apply security patches for CVE-2024-39499 through CVE-2024-39503

IT Operations 48h

Mitigations

Patch Aruba EdgeConnect software to the latest version

immediate IT Operations

CVE-2024-39499, CVE-2024-39500, CVE-2024-39501, CVE-2024-39502, CVE-2024-39503