VYPR

Vendor CVEs

Arubanetworks

All CVEs

714 total · sorted by risk
  • CVE-2020-24623MedSep 18, 2020
    risk 0.42cvss 6.5epss 0.01

    A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware Esxi v2.5.2 and HPE Universal API Framework for Microsoft…

  • CVE-2018-0489MedFeb 27, 2018
    risk 0.42cvss 6.5epss 0.02

    Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML…

  • CVE-2017-5787MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.02

    A remote denial of service vulnerability in HPE Version Control Repository Manager (VCRM) in all versions prior to 7.6 was found.

  • CVE-2017-5785MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.01

    A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-5784MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.01

    A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-5780MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.02

    A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-12543MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.01

    A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found.

  • CVE-2016-8514MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.02

    A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.

  • CVE-2023-43508MedOct 25, 2023
    risk 0.41cvss 6.3epss 0.00

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of these vulnerabilities allow an attacker…

  • CVE-2023-25594MedMar 22, 2023
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of this vulnerability allows an attacker…

  • CVE-2021-40995MedOct 15, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has…

  • CVE-2021-40994MedOct 15, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has…

  • CVE-2021-34616MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-34615MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-34613MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-34612MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-34614MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-26971MedMar 5, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run arbitrary commands on…

  • CVE-2021-26970MedMar 5, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run arbitrary commands on…

  • CVE-2025-37138MedOct 14, 2025
    risk 0.40cvss 6.2epss 0.01

    An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could…

  • CVE-2024-22444MedJul 24, 2024
    risk 0.40cvss 6.1epss 0.00

    A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary…

  • CVE-2015-1390MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.

  • CVE-2023-37439MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.00

    Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these…

  • CVE-2023-35978MedJul 5, 2023
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface. A successful exploit could allow an attacker to execute arbitrary script code in a…

  • CVE-2022-43527MedJan 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to…

  • CVE-2022-43526MedJan 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to…

  • CVE-2022-43525MedJan 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to…

  • CVE-2022-37927MedDec 12, 2022
    risk 0.40cvss 6.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD).

  • CVE-2022-37925MedDec 12, 2022
    risk 0.40cvss 6.1epss 0.01

    A vulnerability within the web-based management interface of Aruba EdgeConnect Enterprise could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary…

  • CVE-2022-37896MedOct 7, 2022
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in…

  • CVE-2022-23659MedMay 16, 2022
    risk 0.40cvss 6.1epss 0.01

    A remote reflected cross site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2021-41003MedMar 2, 2022
    risk 0.40cvss 6.1epss 0.01

    Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360…

  • CVE-2021-37731MedSep 7, 2021
    risk 0.40cvss 6.2epss 0.00

    A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and…

  • CVE-2021-29149MedJul 22, 2021
    risk 0.40cvss 6.2epss 0.00

    A local bypass security restrictions vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): Aruba…

  • CVE-2021-29148MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    A local cross-site scripting (XSS) vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): Aruba AOS-CX…

  • CVE-2021-34617MedJul 19, 2021
    risk 0.40cvss 6.1epss 0.01

    A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.13 and below; Aruba Instant 6.5.x: 6.5.4.13 and below; Aruba Instant 8.3.x: 8.3.0.7 and below; Aruba Instant…

  • CVE-2021-29137MedApr 29, 2021
    risk 0.40cvss 6.1epss 0.01

    A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.

  • CVE-2021-26967MedMar 5, 2021
    risk 0.40cvss 6.1epss 0.01

    A remote reflected cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow a remote attacker to conduct a reflected cross-site…

  • CVE-2021-26682MedFeb 23, 2021
    risk 0.40cvss 6.1epss 0.01

    A remote reflected cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the guest portal interface of ClearPass could allow a remote attacker to conduct a reflected…

  • CVE-2021-26678MedFeb 23, 2021
    risk 0.40cvss 6.1epss 0.01

    A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface of ClearPass could allow an unauthenticated remote…

  • CVE-2019-5320MedAug 26, 2020
    risk 0.40cvss 6.1epss 0.01

    Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Cross Site Scripting in the web UI, leading to injection of code.

  • CVE-2019-5314MedSep 13, 2019
    risk 0.40cvss 6.1epss 0.01

    Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.

  • CVE-2018-7064MedMay 10, 2019
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or…

  • CVE-2017-9002MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.01

    All versions of Aruba ClearPass prior to 6.6.8 contain reflected cross-site scripting vulnerabilities. By exploiting this vulnerability, an attacker who can trick a logged-in ClearPass administrative user into clicking a link could obtain sensitive information, such as session…

  • CVE-2016-4406MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.03

    A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.

  • CVE-2025-27079MedApr 8, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system…

  • CVE-2026-73756MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of…

  • CVE-2024-5486MedJul 30, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further…

  • CVE-2024-33513MedMay 1, 2024
    risk 0.38cvss 5.9epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected service.

  • CVE-2023-43509MedOct 25, 2023
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into…

Page 11 of 15