Arubanetworks
arubanetworks
578 CVEs • 213 products
Products (213)
Click to collapseToggle
Products (213)
Click to collapse
CVEs (578)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Arubanetworks 1Clearpass Policy Manager Nov 21, 2024 Feb 23, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass CLI could allow remote authentic...Show more |
1Arubanetworks 1Clearpass Policy Manager Nov 21, 2024 Feb 23, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management int...Show more |
1Arubanetworks 1Clearpass Policy Manager Nov 21, 2024 Feb 23, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPa...Show more |
2Arubanetworks Hpe153500 Firmware 3500 Yl Firmware6200 Yl Firmware+12 moreNov 21, 2024 Feb 9, 2021 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's man...Show more |
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be...Show more |
1Arubanetworks 1Airwave Glass Nov 21, 2024 Jan 15, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 There is a vulnerability caused by insufficient input validation that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete...Show more |
1Arubanetworks 1Airwave Glass Nov 21, 2024 Jan 15, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation can lead to complete co...Show more |
Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root on the underlying ho...Show more |
1Arubanetworks 1Edgeconnect Enterprise Dec 12, 2024 Dec 11, 2020 N/A· v4 6.8 MEDIUM· v3 8.5 HIGH· v2 The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to...Show more |
1Arubanetworks 1Edgeconnect Enterprise Dec 12, 2024 Dec 11, 2020 N/A· v4 6.8 MEDIUM· v3 8.5 HIGH· v2 A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the Edg...Show more |
Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this vulnerability this could lead to remote compromise of system integrity by allowing an attac...Show more |
1Arubanetworks 2Arubaos Sd WanNov 21, 2024 Dec 11, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Ga...Show more |
1Arubanetworks 2Arubaos Sd WanNov 21, 2024 Dec 11, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (821...Show more |
A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
1Arubanetworks 1Airwave Glass Nov 21, 2024 Nov 4, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
1Arubanetworks 1Airwave Glass Nov 21, 2024 Oct 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
1Arubanetworks 1Airwave Glass Nov 21, 2024 Oct 26, 2020 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
1Arubanetworks 1Airwave Glass Nov 21, 2024 Oct 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |
A remote execution of arbitrary commandss vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. |