VYPR

Vendor CVEs

Arubanetworks

All CVEs

714 total · sorted by risk
  • CVE-2021-26968MedMar 5, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow an authenticated remote attacker to conduct a…

  • CVE-2020-7110MedApr 16, 2020
    risk 0.31cvss 4.8epss 0.01

    ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack. Resolution: Fixed in 6.7.13, 6.8.4,…

  • CVE-2022-43529MedJan 5, 2023
    risk 0.30cvss 4.6epss 0.00

    A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persist a session after a password reset or similar session clearing event. Successful exploitation of this vulnerability could allow an…

  • CVE-2023-39268MedAug 29, 2023
    risk 0.29cvss 4.5epss 0.01

    A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying…

  • CVE-2023-25596MedMar 22, 2023
    risk 0.29cvss 4.5epss 0.00

    A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain…

  • CVE-2022-37910MedDec 12, 2022
    risk 0.29cvss 4.4epss 0.01

    A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system.

  • CVE-2021-25141MedFeb 9, 2021
    risk 0.29cvss 4.4epss 0.00

    A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing…

  • CVE-2026-23812MedMar 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for…

  • CVE-2026-23811MedMar 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a…

  • CVE-2026-23810MedMar 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Temporal Key (GTK) associated with…

  • CVE-2023-45627MedNov 14, 2023
    risk 0.28cvss 4.3epss 0.01

    An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

  • CVE-2022-23689MedSep 6, 2022
    risk 0.28cvss 4.3epss 0.00

    Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX…

  • CVE-2022-23688MedSep 6, 2022
    risk 0.28cvss 4.3epss 0.00

    Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX…

  • CVE-2022-23687MedSep 6, 2022
    risk 0.28cvss 4.3epss 0.00

    Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX…

  • CVE-2022-23686MedSep 6, 2022
    risk 0.28cvss 4.3epss 0.00

    Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX…

  • CVE-2021-29151MedJul 8, 2021
    risk 0.28cvss 4.3epss 0.01

    A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2017-8973MedFeb 15, 2018
    risk 0.28cvss 4.3epss 0.01

    An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

  • CVE-2017-8972MedFeb 15, 2018
    risk 0.28cvss 4.3epss 0.01

    A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

  • CVE-2017-8971MedFeb 15, 2018
    risk 0.28cvss 4.3epss 0.01

    A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

  • CVE-2023-30510MedMay 16, 2023
    risk 0.27cvss 4.1epss 0.01

    A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which…

  • CVE-2022-37911LowDec 12, 2022
    risk 0.25cvss 3.8epss 0.01

    Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources,…

  • CVE-2024-25616LowMar 5, 2024
    risk 0.24cvss 3.7epss 0.00

    Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the…

  • CVE-2024-22438LowApr 15, 2024
    risk 0.23cvss 3.5epss 0.00

    A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820 Network switches. The vulnerability could be remotely exploited to allow execution of malicious code.

  • CVE-2016-8535LowFeb 15, 2018
    risk 0.23cvss 3.5epss 0.01

    A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2015-1389May 28, 2015
    risk 0.04cvss —epss 0.07

    Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary web script or HTML via the username parameter to tips/tipsLoginSubmit.action.

  • CVE-2007-6054Nov 20, 2007
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /screens URI,…

  • CVE-2026-12602HigJun 22, 2026
    risk 0.00cvss —epss 0.00

    Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program…

  • CVE-2015-5430Aug 27, 2015
    risk 0.00cvss —epss 0.03

    HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2015-5409Aug 26, 2015
    risk 0.00cvss —epss 0.02

    Buffer overflow in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

  • CVE-2015-4132May 28, 2015
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-1551May 28, 2015
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.4 allows remote administrators to read arbitrary files via unspecified vectors.

  • CVE-2015-1550May 28, 2015
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors.

  • CVE-2015-1392May 28, 2015
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2014-6628May 28, 2015
    risk 0.00cvss —epss 0.02

    Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via unspecified vectors.

  • CVE-2015-1388Mar 24, 2015
    risk 0.00cvss —epss 0.01

    The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2015-1348Feb 3, 2015
    risk 0.00cvss —epss 0.01

    Heap-based buffer overflow in Aruba Instant (IAP) with firmware before 4.0.0.7 and 4.1.x before 4.1.1.2 allows remote attackers to cause a denial of service (crash or reset to factory default) via a malformed frame to the wireless interface.

  • CVE-2014-8368Nov 25, 2014
    risk 0.00cvss —epss 0.03

    The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors.

  • CVE-2014-8367Nov 25, 2014
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2014-6627Nov 19, 2014
    risk 0.00cvss —epss 0.02

    Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-5342.

  • CVE-2014-6626Nov 19, 2014
    risk 0.00cvss —epss 0.02

    Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown vectors.

  • CVE-2014-6625Nov 19, 2014
    risk 0.00cvss —epss 0.02

    The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecified vectors.

  • CVE-2014-6624Nov 19, 2014
    risk 0.00cvss —epss 0.01

    The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unspecified vectors.

  • CVE-2014-6622Nov 19, 2014
    risk 0.00cvss —epss 0.01

    Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors.

  • CVE-2014-6621Nov 19, 2014
    risk 0.00cvss —epss 0.01

    Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which allows remote attackers to obtain version numbers, module configuration, and other sensitive information by reading the page.

  • CVE-2014-5342Nov 19, 2014
    risk 0.00cvss —epss 0.03

    Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-6627.

  • CVE-2014-6623Nov 7, 2014
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to hijack the authentication of a logged in user via unspecified vectors.

  • CVE-2014-6620Nov 7, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2014-7299Oct 8, 2014
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authentication, and obtain potentially sensitive information or add guest accounts, via an SSH session.

  • CVE-2014-2593Aug 29, 2014
    risk 0.00cvss —epss 0.02

    The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.

  • CVE-2014-4031Jul 15, 2014
    risk 0.00cvss —epss 0.01

    The Policy Manager in Aruba Networks ClearPass 5.x, 6.0.x, 6.1.x through 6.1.4.61696, 6.2.x through 6.2.6.62196, and 6.3.x before 6.3.4 allows remote authenticated users to obtain database credentials via unspecified vectors.

Page 14 of 15