VYPR

Vendor CVEs

Arubanetworks

All CVEs

714 total · sorted by risk
  • CVE-2024-42399MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42398MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-31482MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-31481MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-31480MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-31479MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-31478MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilites result in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-33518MedMay 1, 2024
    risk 0.34cvss 5.3epss 0.01

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-33517MedMay 1, 2024
    risk 0.34cvss 5.3epss 0.01

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-33516MedMay 1, 2024
    risk 0.34cvss 5.3epss 0.01

    An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.

  • CVE-2024-33515MedMay 1, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-33514MedMay 1, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-25615MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

  • CVE-2023-44983MedDec 19, 2023
    risk 0.34cvss 5.3epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aruba.It Aruba HiSpeed Cache.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.6.

  • CVE-2023-35979MedJul 5, 2023
    risk 0.34cvss 5.3epss 0.01

    There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in a Denial-of-Service (DoS) condition affecting the web-based management interface of the…

  • CVE-2022-37909MedDec 12, 2022
    risk 0.34cvss 5.3epss 0.00

    Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of…

  • CVE-2020-7120MedFeb 23, 2021
    risk 0.34cvss 5.3epss 0.00

    A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users to cause a buffer overflow condition. A successful…

  • CVE-2026-44874MedMay 12, 2026
    risk 0.32cvss 4.9epss 0.00

    A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of…

  • CVE-2025-37145MedOct 14, 2025
    risk 0.32cvss 4.9epss 0.00

    Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed…

  • CVE-2025-37144MedOct 14, 2025
    risk 0.32cvss 4.9epss 0.00

    Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed…

  • CVE-2025-37143MedOct 14, 2025
    risk 0.32cvss 4.9epss 0.00

    An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated malicious actor to download arbitrary files through carefully…

  • CVE-2025-37142MedOct 14, 2025
    risk 0.32cvss 4.9epss 0.00

    Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

  • CVE-2025-37141MedOct 14, 2025
    risk 0.32cvss 4.9epss 0.00

    Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

  • CVE-2025-37140MedOct 14, 2025
    risk 0.32cvss 4.9epss 0.00

    Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

  • CVE-2025-27085MedApr 8, 2025
    risk 0.32cvss 4.9epss 0.01

    Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an…

  • CVE-2024-31483MedMay 14, 2024
    risk 0.32cvss 4.9epss 0.00

    An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.

  • CVE-2024-26303MedMar 26, 2024
    risk 0.32cvss 4.9epss 0.01

    Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon

  • CVE-2023-30509MedMay 16, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system…

  • CVE-2023-30508MedMay 16, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system…

  • CVE-2023-30507MedMay 16, 2023
    risk 0.32cvss 4.9epss 0.01

    Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system…

  • CVE-2023-22777MedMar 1, 2023
    risk 0.32cvss 4.9epss 0.01

    An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.

  • CVE-2023-22776MedMar 1, 2023
    risk 0.32cvss 4.9epss 0.01

    An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files.

  • CVE-2022-44532MedDec 12, 2022
    risk 0.32cvss 4.9epss 0.01

    An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in…

  • CVE-2022-43518MedDec 12, 2022
    risk 0.32cvss 4.9epss 0.01

    An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba…

  • CVE-2022-37895MedOct 7, 2022
    risk 0.32cvss 4.9epss 0.01

    An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS…

  • CVE-2022-23668MedMay 16, 2022
    risk 0.32cvss 4.9epss 0.01

    A remote authenticated server-side request forgery (ssrf) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manage that address this…

  • CVE-2021-37733MedSep 7, 2021
    risk 0.32cvss 4.9epss 0.01

    A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.11, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and…

  • CVE-2020-7119MedSep 4, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user.

  • CVE-2020-7113MedApr 16, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts. Resolution: Fixed in 6.7.10, 6.8.1, 6.9.0…

  • CVE-2025-25039MedFeb 4, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a lower…

  • CVE-2024-53672MedDec 3, 2024
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the…

  • CVE-2024-51773MedDec 3, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the…

  • CVE-2024-26302MedFeb 27, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially…

  • CVE-2023-43510MedOct 25, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a non-privileged user on the…

  • CVE-2023-22778MedMar 1, 2023
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's…

  • CVE-2022-43528MedJan 5, 2023
    risk 0.31cvss 4.8epss 0.00

    Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code. Successful exploitation allows an attacker to login using only a username and password and successfully bypass MFA requirements…

  • CVE-2022-23675MedMay 17, 2022
    risk 0.31cvss 4.8epss 0.01

    A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this…

  • CVE-2021-37715MedAug 26, 2021
    risk 0.31cvss 4.8epss 0.00

    A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.13.0. Aruba has released upgrades for the Aruba AirWave Management Platform that address this security vulnerability.

  • CVE-2021-29139MedApr 29, 2021
    risk 0.31cvss 4.8epss 0.00

    A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-29142MedApr 29, 2021
    risk 0.31cvss 4.8epss 0.00

    A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.