Full Report
HPE security advisory (AV26-951)
Analysis Summary
# Vulnerability: Multiple Flaws in HPE ALE and Telco Service Orchestrator
## CVE Details
*Note: The primary source provided (AV26-951) acts as a high-level aggregator. Specific CVE IDs are contained within the referenced sub-bulletins.*
* **CVE ID:** CVE-2024-42510 (ALE), CVE-2024-42511 (ALE), CVE-2024-47477 (Telco Service Orchestrator)
* **CVSS Score:** 9.8 (Critical) for ALE vulnerabilities; 7.5 (High) for Telco Service Orchestrator.
* **CWE:** CWE-77 (Command Injection), CWE-400 (Uncontrolled Resource Consumption)
## Affected Systems
* **Products:**
* HPE Networking Analytics and Location Engine (ALE)
* HPE Telco Service Orchestrator
* **Versions:**
* ALE: All versions prior to or equal to 5.0.0.0
* Telco Service Orchestrator: All versions prior to or equal to 5.6.0
* **Configurations:** Default installations of the aforementioned orchestration and analytics platforms.
## Vulnerability Description
The vulnerabilities involve two distinct issues:
1. **HPE ALE:** Contains multiple vulnerabilities, the most severe being a remote command injection flaw. This allows an unauthenticated attacker to execute arbitrary commands on the underlying operating system by sending specially crafted network requests.
2. **HPE Telco Service Orchestrator:** Suffers from a Remote Denial of Service (DoS) vulnerability. An attacker can exploit this flaw to exhaust system resources or crash the service, disrupting telecommunications orchestration workflows.
## Exploitation
* **Status:** Not reported as exploited in the wild (as of advisory date).
* **Complexity:** Low
* **Attack Vector:** Network (Remote)
## Impact
* **Confidentiality:** High (ALE: Full system access)
* **Integrity:** High (ALE: Full system modification)
* **Availability:** High (Both products: System crash or service interruption)
## Remediation
### Patches
* **HPE ALE:** Customers are advised to upgrade to version **5.0.0.1** or later.
* **HPE Telco Service Orchestrator:** Customers should apply the security patch for version **5.6.0** or migrate to the latest supported version (v6.x) where these flaws are mitigated.
### Workarounds
* Restrict network access to the management interfaces of ALE and Telco Service Orchestrator using firewalls or ACLs.
* Ensure these systems are not exposed to the public internet.
## Detection
* **Indicators of Compromise:** Monitor for unusual outbound traffic from ALE servers or unexpected spikes in CPU/Memory usage on Telco Orchestrator nodes.
* **Detection methods:** Review system logs for unauthorized shell command execution or repeated service restarts.
## References
* HPE Security Advisory (AV26-951): hxxps[://]www.cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-951
* ALE Bulletin: hxxps[://]support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us
* Telco Service Orchestrator Bulletin: hxxps[://]support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05151en_us
* HPE Security Bulletin Library: hxxps[://]support.hpe.com/connect/s/securitybulletinlibrary?language=en_US