VYPR

Airwave

by Arubanetworks

CVEs (42)

  • CVE-2015-2202HigSep 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.

  • CVE-2015-2201HigSep 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.

  • CVE-2021-25152HigApr 28, 2021
    risk 0.47cvss 7.2epss 0.01

    A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-26963HigMar 5, 2021
    risk 0.47cvss 7.2epss 0.03

    A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A…

  • CVE-2021-26962HigMar 5, 2021
    risk 0.47cvss 7.2epss 0.03

    A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A…

  • CVE-2019-5326HigFeb 27, 2020
    risk 0.47cvss 7.2epss 0.02

    An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application…

  • CVE-2019-5323HigFeb 27, 2020
    risk 0.47cvss 7.2epss 0.03

    There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.

  • CVE-2021-26964HigMar 5, 2021
    risk 0.46cvss 7.1epss 0.01

    A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an authenticated remote attacker to improperly access and modify…

  • CVE-2023-4896MedOct 17, 2023
    risk 0.44cvss 6.8epss 0.00

    A vulnerability exists which allows an authenticated attacker to access sensitive information on the AirWave Management Platform web-based management interface. Successful exploitation allows the attacker to gain access to some data that could be further exploited to laterally…

  • CVE-2016-8527MedAug 6, 2018
    risk 0.44cvss 6.1epss 0.13

    Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative…

  • CVE-2021-25164MedApr 28, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-26969MedMar 5, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML entities a vulnerability exists in the web-based management interface of AirWave. A…

  • CVE-2021-26966MedMar 5, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection attacks against the AirWave…

  • CVE-2021-26965MedMar 5, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection attacks against the AirWave…

  • CVE-2021-26971MedMar 5, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run arbitrary commands on…

  • CVE-2021-26970MedMar 5, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run arbitrary commands on…

  • CVE-2015-1390MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.

  • CVE-2021-29137MedApr 29, 2021
    risk 0.40cvss 6.1epss 0.01

    A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-26967MedMar 5, 2021
    risk 0.40cvss 6.1epss 0.01

    A remote reflected cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow a remote attacker to conduct a reflected cross-site…

  • CVE-2021-37715MedAug 26, 2021
    risk 0.31cvss 4.8epss 0.00

    A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.13.0. Aruba has released upgrades for the Aruba AirWave Management Platform that address this security vulnerability.