Skip to main content

Vendor archive

arubanetworks CVEs

Beta · best-effort

588 CVEs tagged to vendor arubanetworks83 Critical, 291 High, 211 Medium, 3 Low, 0 Unrated.

CVE-2015-4649

Published Aug 29, 2017

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via unspecified vectors, a different…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3657

Published Aug 29, 2017

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Admin" privileges via unspecified…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3656

Published Aug 29, 2017

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to prop…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3655

Published Aug 29, 2017

Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to hijack the authentication…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3654

Published Aug 29, 2017

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via unspecified vectors, a different…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3653

Published Aug 29, 2017

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files within the underlying operating…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5638

Published Mar 11, 2017

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload atte…

CVSS 9.8 · Critical
evidence mentions
76
Buzz score
75.0
KEV listed

CVE-2015-4132

Published May 28, 2015

Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HT…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-1551

Published May 28, 2015

Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.4 allows remote administrators to read arbitrary files via unspecified vectors.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1550

Published May 28, 2015

Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1392

Published May 28, 2015

Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to execute arbitrary SQL commands via unspecified…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1389

Published May 28, 2015

Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary web script or HTML via the user…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6628

Published May 28, 2015

Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via unspecified vectors.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1388

Published Mar 24, 2015

The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attac…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8368

Published Nov 25, 2014

The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-8367

Published Nov 25, 2014

SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6627

Published Nov 19, 2014

Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-6626

Published Nov 19, 2014

Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass aut…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-6625

Published Nov 19, 2014

The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-6624

Published Nov 19, 2014

The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6622

Published Nov 19, 2014

Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6621

Published Nov 19, 2014

Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which allows remote attackers to obta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5342

Published Nov 19, 2014

Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 551-575 of 588 CVEsPage 23 of 24