Vendor CVEs
Arubanetworks
All CVEs
714 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26968 | Med | 0.31 | 4.8 | 0.01 | Mar 5, 2021 | A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow an authenticated remote attacker to conduct a… | ||
| CVE-2020-7110 | Med | 0.31 | 4.8 | 0.01 | Apr 16, 2020 | ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack. Resolution: Fixed in 6.7.13, 6.8.4,… | ||
| CVE-2022-43529 | Med | 0.30 | 4.6 | 0.00 | Jan 5, 2023 | A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persist a session after a password reset or similar session clearing event. Successful exploitation of this vulnerability could allow an… | ||
| CVE-2023-39268 | Med | 0.29 | 4.5 | 0.01 | Aug 29, 2023 | A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying… | ||
| CVE-2023-25596 | Med | 0.29 | 4.5 | 0.00 | Mar 22, 2023 | A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain… | ||
| CVE-2022-37910 | Med | 0.29 | 4.4 | 0.01 | Dec 12, 2022 | A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system. | ||
| CVE-2021-25141 | Med | 0.29 | 4.4 | 0.00 | Feb 9, 2021 | A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing… | ||
| CVE-2026-23812 | Med | 0.28 | 4.3 | 0.00 | Mar 4, 2026 | A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for… | ||
| CVE-2026-23811 | Med | 0.28 | 4.3 | 0.00 | Mar 4, 2026 | A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a… | ||
| CVE-2026-23810 | Med | 0.28 | 4.3 | 0.00 | Mar 4, 2026 | A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Temporal Key (GTK) associated with… | ||
| CVE-2023-45627 | Med | 0.28 | 4.3 | 0.01 | Nov 14, 2023 | An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point. | ||
| CVE-2022-23689 | Med | 0.28 | 4.3 | 0.00 | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX… | ||
| CVE-2022-23688 | Med | 0.28 | 4.3 | 0.00 | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX… | ||
| CVE-2022-23687 | Med | 0.28 | 4.3 | 0.00 | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX… | ||
| CVE-2022-23686 | Med | 0.28 | 4.3 | 0.00 | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX… | ||
| CVE-2021-29151 | Med | 0.28 | 4.3 | 0.01 | Jul 8, 2021 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | ||
| CVE-2017-8973 | Med | 0.28 | 4.3 | 0.01 | Feb 15, 2018 | An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. | ||
| CVE-2017-8972 | Med | 0.28 | 4.3 | 0.01 | Feb 15, 2018 | A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. | ||
| CVE-2017-8971 | Med | 0.28 | 4.3 | 0.01 | Feb 15, 2018 | A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. | ||
| CVE-2023-30510 | Med | 0.27 | 4.1 | 0.01 | May 16, 2023 | A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which… | ||
| CVE-2022-37911 | Low | 0.25 | 3.8 | 0.01 | Dec 12, 2022 | Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources,… | ||
| CVE-2024-25616 | Low | 0.24 | 3.7 | 0.00 | Mar 5, 2024 | Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the… | ||
| CVE-2024-22438 | Low | 0.23 | 3.5 | 0.00 | Apr 15, 2024 | A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820 Network switches. The vulnerability could be remotely exploited to allow execution of malicious code. | ||
| CVE-2016-8535 | Low | 0.23 | 3.5 | 0.01 | Feb 15, 2018 | A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found. | ||
| CVE-2015-1389 | 0.04 | — | 0.07 | May 28, 2015 | Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary web script or HTML via the username parameter to tips/tipsLoginSubmit.action. | |||
| CVE-2007-6054 | 0.03 | — | 0.02 | Nov 20, 2007 | Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /screens URI,… | |||
| CVE-2026-12602 | Hig | 0.00 | — | 0.00 | Jun 22, 2026 | Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program… | ||
| CVE-2015-5430 | 0.00 | — | 0.03 | Aug 27, 2015 | HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information via unspecified vectors. | |||
| CVE-2015-5409 | 0.00 | — | 0.02 | Aug 26, 2015 | Buffer overflow in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors. | |||
| CVE-2015-4132 | 0.00 | — | 0.01 | May 28, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2015-1551 | 0.00 | — | 0.01 | May 28, 2015 | Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.4 allows remote administrators to read arbitrary files via unspecified vectors. | |||
| CVE-2015-1550 | 0.00 | — | 0.02 | May 28, 2015 | Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors. | |||
| CVE-2015-1392 | 0.00 | — | 0.01 | May 28, 2015 | Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to execute arbitrary SQL commands via unspecified vectors. | |||
| CVE-2014-6628 | 0.00 | — | 0.02 | May 28, 2015 | Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via unspecified vectors. | |||
| CVE-2015-1388 | 0.00 | — | 0.01 | Mar 24, 2015 | The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors. | |||
| CVE-2015-1348 | 0.00 | — | 0.01 | Feb 3, 2015 | Heap-based buffer overflow in Aruba Instant (IAP) with firmware before 4.0.0.7 and 4.1.x before 4.1.1.2 allows remote attackers to cause a denial of service (crash or reset to factory default) via a malformed frame to the wireless interface. | |||
| CVE-2014-8368 | 0.00 | — | 0.03 | Nov 25, 2014 | The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors. | |||
| CVE-2014-8367 | 0.00 | — | 0.02 | Nov 25, 2014 | SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||
| CVE-2014-6627 | 0.00 | — | 0.02 | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-5342. | |||
| CVE-2014-6626 | 0.00 | — | 0.02 | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown vectors. | |||
| CVE-2014-6625 | 0.00 | — | 0.02 | Nov 19, 2014 | The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecified vectors. | |||
| CVE-2014-6624 | 0.00 | — | 0.01 | Nov 19, 2014 | The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unspecified vectors. | |||
| CVE-2014-6622 | 0.00 | — | 0.01 | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors. | |||
| CVE-2014-6621 | 0.00 | — | 0.01 | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which allows remote attackers to obtain version numbers, module configuration, and other sensitive information by reading the page. | |||
| CVE-2014-5342 | 0.00 | — | 0.03 | Nov 19, 2014 | Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-6627. | |||
| CVE-2014-6623 | 0.00 | — | 0.01 | Nov 7, 2014 | Cross-site request forgery (CSRF) vulnerability in the Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to hijack the authentication of a logged in user via unspecified vectors. | |||
| CVE-2014-6620 | 0.00 | — | 0.01 | Nov 7, 2014 | Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2014-7299 | 0.00 | — | 0.02 | Oct 8, 2014 | Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authentication, and obtain potentially sensitive information or add guest accounts, via an SSH session. | |||
| CVE-2014-2593 | 0.00 | — | 0.02 | Aug 29, 2014 | The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands. | |||
| CVE-2014-4031 | 0.00 | — | 0.01 | Jul 15, 2014 | The Policy Manager in Aruba Networks ClearPass 5.x, 6.0.x, 6.1.x through 6.1.4.61696, 6.2.x through 6.2.6.62196, and 6.3.x before 6.3.4 allows remote authenticated users to obtain database credentials via unspecified vectors. |
- risk 0.31cvss 4.8epss 0.01
A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow an authenticated remote attacker to conduct a…
- risk 0.31cvss 4.8epss 0.01
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack. Resolution: Fixed in 6.7.13, 6.8.4,…
- risk 0.30cvss 4.6epss 0.00
A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persist a session after a password reset or similar session clearing event. Successful exploitation of this vulnerability could allow an…
- risk 0.29cvss 4.5epss 0.01
A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying…
- risk 0.29cvss 4.5epss 0.00
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain…
- risk 0.29cvss 4.4epss 0.01
A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system.
- risk 0.29cvss 4.4epss 0.00
A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing…
- risk 0.28cvss 4.3epss 0.00
A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for…
- risk 0.28cvss 4.3epss 0.00
A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a…
- risk 0.28cvss 4.3epss 0.00
A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Temporal Key (GTK) associated with…
- risk 0.28cvss 4.3epss 0.01
An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.
- risk 0.28cvss 4.3epss 0.00
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX…
- risk 0.28cvss 4.3epss 0.00
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX…
- risk 0.28cvss 4.3epss 0.00
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX…
- risk 0.28cvss 4.3epss 0.00
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX…
- risk 0.28cvss 4.3epss 0.01
A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
- risk 0.28cvss 4.3epss 0.01
An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
- risk 0.28cvss 4.3epss 0.01
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
- risk 0.28cvss 4.3epss 0.01
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
- risk 0.27cvss 4.1epss 0.01
A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which…
- risk 0.25cvss 3.8epss 0.01
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources,…
- risk 0.24cvss 3.7epss 0.00
Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the…
- risk 0.23cvss 3.5epss 0.00
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820 Network switches. The vulnerability could be remotely exploited to allow execution of malicious code.
- risk 0.23cvss 3.5epss 0.01
A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found.
- CVE-2015-1389May 28, 2015risk 0.04cvss —epss 0.07
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary web script or HTML via the username parameter to tips/tipsLoginSubmit.action.
- CVE-2007-6054Nov 20, 2007risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /screens URI,…
- risk 0.00cvss —epss 0.00
Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program…
- CVE-2015-5430Aug 27, 2015risk 0.00cvss —epss 0.03
HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information via unspecified vectors.
- CVE-2015-5409Aug 26, 2015risk 0.00cvss —epss 0.02
Buffer overflow in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.
- CVE-2015-4132May 28, 2015risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2015-1551May 28, 2015risk 0.00cvss —epss 0.01
Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.4 allows remote administrators to read arbitrary files via unspecified vectors.
- CVE-2015-1550May 28, 2015risk 0.00cvss —epss 0.02
Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors.
- CVE-2015-1392May 28, 2015risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to execute arbitrary SQL commands via unspecified vectors.
- CVE-2014-6628May 28, 2015risk 0.00cvss —epss 0.02
Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via unspecified vectors.
- CVE-2015-1388Mar 24, 2015risk 0.00cvss —epss 0.01
The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors.
- CVE-2015-1348Feb 3, 2015risk 0.00cvss —epss 0.01
Heap-based buffer overflow in Aruba Instant (IAP) with firmware before 4.0.0.7 and 4.1.x before 4.1.1.2 allows remote attackers to cause a denial of service (crash or reset to factory default) via a malformed frame to the wireless interface.
- CVE-2014-8368Nov 25, 2014risk 0.00cvss —epss 0.03
The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors.
- CVE-2014-8367Nov 25, 2014risk 0.00cvss —epss 0.02
SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVE-2014-6627Nov 19, 2014risk 0.00cvss —epss 0.02
Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-5342.
- CVE-2014-6626Nov 19, 2014risk 0.00cvss —epss 0.02
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown vectors.
- CVE-2014-6625Nov 19, 2014risk 0.00cvss —epss 0.02
The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecified vectors.
- CVE-2014-6624Nov 19, 2014risk 0.00cvss —epss 0.01
The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unspecified vectors.
- CVE-2014-6622Nov 19, 2014risk 0.00cvss —epss 0.01
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors.
- CVE-2014-6621Nov 19, 2014risk 0.00cvss —epss 0.01
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which allows remote attackers to obtain version numbers, module configuration, and other sensitive information by reading the page.
- CVE-2014-5342Nov 19, 2014risk 0.00cvss —epss 0.03
Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-6627.
- CVE-2014-6623Nov 7, 2014risk 0.00cvss —epss 0.01
Cross-site request forgery (CSRF) vulnerability in the Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to hijack the authentication of a logged in user via unspecified vectors.
- CVE-2014-6620Nov 7, 2014risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2014-7299Oct 8, 2014risk 0.00cvss —epss 0.02
Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authentication, and obtain potentially sensitive information or add guest accounts, via an SSH session.
- CVE-2014-2593Aug 29, 2014risk 0.00cvss —epss 0.02
The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.
- CVE-2014-4031Jul 15, 2014risk 0.00cvss —epss 0.01
The Policy Manager in Aruba Networks ClearPass 5.x, 6.0.x, 6.1.x through 6.1.4.61696, 6.2.x through 6.2.6.62196, and 6.3.x before 6.3.4 allows remote authenticated users to obtain database credentials via unspecified vectors.
Page 14 of 15