Skip to main content

Vendor archive

arubanetworks CVEs

Beta · best-effort

588 CVEs tagged to vendor arubanetworks83 Critical, 291 High, 211 Medium, 3 Low, 0 Unrated.

CVE-2025-25039

Published Feb 4, 2025

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the un…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23060

Published Feb 4, 2025

A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could al…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23059

Published Feb 4, 2025

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfu…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23058

Published Feb 4, 2025

A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to dat…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23057

Published Jan 28, 2025

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS)…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23056

Published Jan 28, 2025

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS)…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23055

Published Jan 28, 2025

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS)…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23054

Published Jan 28, 2025

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not al…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23053

Published Jan 28, 2025

A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-53672

Published Dec 3, 2024

A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful explo…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51773

Published Dec 3, 2024

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scr…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51772

Published Dec 3, 2024

An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying hos…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51771

Published Dec 3, 2024

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execu…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42400

Published Aug 6, 2024

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities resul…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42399

Published Aug 6, 2024

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities resul…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42398

Published Aug 6, 2024

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities resul…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42395

Published Aug 6, 2024

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-42394

Published Aug 6, 2024

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-42393

Published Aug 6, 2024

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5486

Published Jul 30, 2024

A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful e…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41916

Published Jul 30, 2024

A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful e…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41915

Published Jul 30, 2024

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPa…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 588 CVEsPage 4 of 24