VYPR

Airwave

by Arubanetworks

CVEs (42)

  • CVE-2023-45616CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful…

  • CVE-2016-2031CriJan 31, 2020
    risk 0.64cvss 9.8epss 0.05

    Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform…

  • CVE-2016-8526HigAug 6, 2018
    risk 0.61cvss 8.8epss 0.10

    Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can…

  • CVE-2021-25151HigApr 28, 2021
    risk 0.58cvss 8.8epss 0.12

    A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2015-1391HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.00

    Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.

  • CVE-2021-25167HigApr 29, 2021
    risk 0.57cvss 8.8epss 0.01

    A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-25166HigApr 29, 2021
    risk 0.57cvss 8.8epss 0.02

    A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-26961HigMar 5, 2021
    risk 0.57cvss 8.8epss 0.01

    A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a…

  • CVE-2021-26960HigMar 5, 2021
    risk 0.57cvss 8.8epss 0.01

    A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a…

  • CVE-2023-45618HigNov 14, 2023
    risk 0.53cvss 8.2epss 0.01

    There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which…

  • CVE-2022-37918HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…

  • CVE-2022-37917HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…

  • CVE-2022-37916HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…

  • CVE-2021-25163HigApr 29, 2021
    risk 0.53cvss 8.1epss 0.01

    A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-25165HigApr 28, 2021
    risk 0.53cvss 8.1epss 0.01

    A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-25153HigApr 28, 2021
    risk 0.53cvss 8.1epss 0.01

    A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-25147HigApr 28, 2021
    risk 0.53cvss 8.1epss 0.01

    A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-25154HigApr 28, 2021
    risk 0.49cvss 7.5epss 0.01

    A remote escalation of privilege vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2016-2032HigJan 31, 2020
    risk 0.49cvss 7.5epss 0.03

    A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672

  • CVE-2025-37163HigNov 18, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying …

Page 1 of 3