Skip to main content

Vendor archive

arubanetworks CVEs

Beta · best-effort

583 CVEs tagged to vendor arubanetworks83 Critical, 287 High, 210 Medium, 3 Low, 0 Unrated.

CVE-2025-37162

Published Nov 18, 2025

A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37161

Published Nov 18, 2025

A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service. Successful exploitation co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37163

Published Nov 18, 2025

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vuln…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37145

Published Oct 14, 2025

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation coul…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37144

Published Oct 14, 2025

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation coul…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37143

Published Oct 14, 2025

An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitati…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37142

Published Oct 14, 2025

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an auth…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37141

Published Oct 14, 2025

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an auth…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37140

Published Oct 14, 2025

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an auth…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37138

Published Oct 14, 2025

An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation o…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37137

Published Oct 14, 2025

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37136

Published Oct 14, 2025

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37135

Published Oct 14, 2025

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37134

Published Oct 14, 2025

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authen…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37133

Published Oct 14, 2025

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authen…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37132

Published Oct 14, 2025

An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful expl…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27085

Published Apr 8, 2025

Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27084

Published Apr 8, 2025

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attac…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27083

Published Apr 8, 2025

Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vul…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27082

Published Apr 8, 2025

Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25039

Published Feb 4, 2025

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the un…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23060

Published Feb 4, 2025

A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could al…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23059

Published Feb 4, 2025

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23058

Published Feb 4, 2025

A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to dat…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23057

Published Jan 28, 2025

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS)…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 583 CVEsPage 3 of 24