VYPR

Vendor CVEs

Arubanetworks

All CVEs

714 total · sorted by risk
  • CVE-2022-37908MedDec 12, 2022
    risk 0.38cvss 5.8epss 0.00

    An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.

  • CVE-2022-37907MedDec 12, 2022
    risk 0.38cvss 5.8epss 0.01

    A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system. A successful attacker can cause a system hang which can only be resolved via a power cycle of the impacted controller.

  • CVE-2022-23678MedSep 6, 2022
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communications that could allow for an attacker in a privileged network position to intercept sensitive information in Aruba Virtual Intranet Access (VIA) client for…

  • CVE-2021-25156MedMar 30, 2021
    risk 0.38cvss 4.9epss 0.40

    A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant…

  • CVE-2020-7126MedOct 26, 2020
    risk 0.38cvss 5.8epss 0.01

    A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

  • CVE-2022-43539MedJan 5, 2023
    risk 0.37cvss 5.7epss 0.00

    A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that allows for…

  • CVE-2025-37185MedJan 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker…

  • CVE-2025-23057MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web…

  • CVE-2025-23056MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web…

  • CVE-2025-23055MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web…

  • CVE-2024-25614MedMar 5, 2024
    risk 0.36cvss 5.5epss 0.01

    There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to denial-of-service conditions and impact the…

  • CVE-2023-45626MedNov 14, 2023
    risk 0.36cvss 5.5epss 0.01

    An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.

  • CVE-2023-37440MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal…

  • CVE-2023-28084MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens

  • CVE-2023-25595MedMar 22, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability allows an attacker to retrieve information that is of a…

  • CVE-2022-43540MedJan 5, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that is of a sensitive nature in Aruba…

  • CVE-2022-37926MedDec 12, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability within the web-based management interface of EdgeConnect Enterprise could allow a remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface by uploading a specially crafted file. A successful exploit could allow an…

  • CVE-2021-25157MedMar 30, 2021
    risk 0.36cvss 4.9epss 0.10

    A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x:…

  • CVE-2018-7073MedAug 6, 2018
    risk 0.36cvss 5.5epss 0.01

    A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

  • CVE-2017-5786MedFeb 15, 2018
    risk 0.36cvss 5.5epss 0.01

    A local Unauthorized Data Modification vulnerability in HPE OfficeConnect Network Switches version PT.02.01 including PT.01.03 through PT.01.14

  • CVE-2017-12553MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12552MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12550MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12549MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12548MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12547MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12546MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2026-44873MedMay 12, 2026
    risk 0.35cvss 5.4epss 0.00

    A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration.…

  • CVE-2026-23809MedMar 4, 2026
    risk 0.35cvss 5.4epss 0.00

    A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass inter-BSSID isolation controls.…

  • CVE-2026-23808MedMar 4, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could allow a remote malicious actor…

  • CVE-2026-23601MedMar 4, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows…

  • CVE-2025-27084MedApr 8, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the…

  • CVE-2023-22791MedMay 8, 2023
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the…

  • CVE-2022-37892MedOct 7, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary…

  • CVE-2022-23690MedSep 6, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of AOS-CX could allow a remote unauthenticated attacker to fingerprint the exact version AOS-CX running on the switch. This allows an attacker to retrieve information which could be used to more precisely target the switch…

  • CVE-2022-23674MedMay 17, 2022
    risk 0.35cvss 5.4epss 0.01

    A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this…

  • CVE-2021-37735MedOct 12, 2021
    risk 0.35cvss 5.3epss 0.01

    A remote denial of service vulnerability was discovered in Aruba Instant version(s): Aruba Instant 6.5.x.x: 6.5.4.18 and below; Aruba Instant 8.5.x.x: 8.5.0.10 and below; Aruba Instant 8.6.x.x: 8.6.0.4 and below. Aruba has released patches for Aruba Instant (IAP) that address…

  • CVE-2021-29146MedApr 29, 2021
    risk 0.35cvss 5.4epss 0.00

    A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-25160MedMar 30, 2021
    risk 0.35cvss 4.9epss 0.07

    A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant…

  • CVE-2017-8970MedFeb 15, 2018
    risk 0.35cvss 5.3epss 0.02

    A remote unauthenticated disclosure of information vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

  • CVE-2017-5827MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A reflected cross site scripting vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

  • CVE-2017-5783MedFeb 15, 2018
    risk 0.35cvss 5.3epss 0.02

    A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-5782MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-12544MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.04

    A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2016-8532MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A cross site scripting vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2016-8531MedFeb 15, 2018
    risk 0.35cvss 5.3epss 0.02

    A remote information disclosure vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2026-23822MedMay 12, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to…

  • CVE-2025-37179MedJan 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific…

  • CVE-2025-37178MedJan 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific…

  • CVE-2024-42400MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

Page 12 of 15