VYPR

Vendor CVEs

Arubanetworks

All CVEs

714 total · sorted by risk
  • CVE-2022-37905MedDec 12, 2022
    risk 0.43cvss 6.6epss 0.01

    Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

  • CVE-2022-37904MedDec 12, 2022
    risk 0.43cvss 6.6epss 0.01

    Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

  • CVE-2025-37177MedJan 13, 2026
    risk 0.42cvss 6.5epss 0.00

    An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete…

  • CVE-2025-37176MedJan 13, 2026
    risk 0.42cvss 6.5epss 0.01

    A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands…

  • CVE-2025-37162MedNov 18, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

  • CVE-2025-37148MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual…

  • CVE-2025-37137MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the…

  • CVE-2025-37136MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the…

  • CVE-2025-37135MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the…

  • CVE-2025-23054MedJan 28, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not allowed by their privilege level. Successful exploitation could allow an attacker to manipulate user…

  • CVE-2025-23053MedJan 28, 2025
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

  • CVE-2024-51772MedDec 3, 2024
    risk 0.42cvss 6.4epss 0.00

    An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…

  • CVE-2024-26301MedFeb 27, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially…

  • CVE-2023-37438MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-37437MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-37436MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-37435MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-37434MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-37433MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-37432MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-37431MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-37430MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-37429MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-35977MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.

  • CVE-2023-35976MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.

  • CVE-2023-35975MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.

  • CVE-2023-22775MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.

  • CVE-2023-22772MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.

  • CVE-2022-37906MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.01

    An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.

  • CVE-2021-46846MedDec 12, 2022
    risk 0.42cvss 6.4epss 0.01

    Cross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5.

  • CVE-2022-37894MedOct 7, 2022
    risk 0.42cvss 6.5epss 0.00

    An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS…

  • CVE-2022-23670MedMay 16, 2022
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2021-41005MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.01

    A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.

  • CVE-2021-40990MedOct 15, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1.…

  • CVE-2021-37734MedOct 12, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote unauthorized read access to files vulnerability was discovered in Aruba Instant version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.19 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba…

  • CVE-2021-37729MedSep 7, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.3, 8.6.0.9, 8.5.0.12, 8.3.0.16, 6.5.4.19, 6.4.4.25. Aruba has released patches for Aruba SD-WAN…

  • CVE-2021-37728MedSep 7, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote path traversal vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.8.0.1, 8.7.1.4, 8.6.0.11, 8.5.0.13. Aruba has released patches for ArubaOS that address this security vulnerability.

  • CVE-2019-5318MedSep 7, 2021
    risk 0.42cvss 6.5epss 0.00

    A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x: all versions prior to 8.8.0.0. Aruba has released patches for ArubaOS that address this security vulnerability.

  • CVE-2021-34618MedJul 19, 2021
    risk 0.42cvss 6.5epss 0.00

    A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.4.x:…

  • CVE-2021-29152MedJul 8, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote denial of service (DoS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-29141MedApr 29, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-29138MedApr 29, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote disclosure of privileged information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-29144MedApr 29, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-25164MedApr 28, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-25145MedMar 30, 2021
    risk 0.42cvss 6.5epss 0.00

    A remote unauthorized disclosure of information vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba…

  • CVE-2021-26969MedMar 5, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML entities a vulnerability exists in the web-based management interface of AirWave. A…

  • CVE-2021-26966MedMar 5, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection attacks against the AirWave…

  • CVE-2021-26965MedMar 5, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote attacker to conduct SQL injection attacks against the AirWave…

  • CVE-2021-26686MedFeb 23, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct…

  • CVE-2021-26685MedFeb 23, 2021
    risk 0.42cvss 6.5epss 0.01

    A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct…

Page 10 of 15