← Back

Arubanetworks

arubanetworks

578 CVEs • 213 products

Products (213)

Click to collapse
Toggle
Arubaos
arubaos
Sd Wan
sd-wan
Clearpass
clearpass
Airwave
airwave
Instant
instant
Aruba Instant
aruba_instant
Airwave Glass
airwave_glass
Aos Cx
aos-cx
2920 Firmware
2920_firmware
2540 Firmware
2540_firmware
2530 Firmware
2530_firmware
3810 Firmware
3810_firmware
2930 Firmware
2930_firmware
2615 Firmware
2615_firmware
2620 Firmware
2620_firmware
2915 Firmware
2915_firmware
203rp Firmware
203rp_firmware
203r Firmware
203r_firmware
203rp
203r
5400r
3810
2920
2930
2540
Vx 500
vx-500
Vx 1000
vx-1000
Vx 2000
vx-2000
Vx 3000
vx-3000
Vx 5000
vx-5000
Vx 6000
vx-6000
Vx 7000
vx-7000
Vx 9000
vx-9000
Vx 8000
vx-8000
Nx 700
nx-700
Nx 1000
nx-1000
Nx 2000
nx-2000
Nx 3000
nx-3000
Nx 5000
nx-5000
Nx 6000
nx-6000
Nx 7000
nx-7000
Nx 8000
nx-8000
Nx 9000
nx-9000
Nx 10k
nx-10k
Nx 11k
nx-11k
2530
Cx 6200f
cx_6200f
Cx 6300
cx_6300
Cx 6400
cx_6400
Cx 8320
cx_8320
Cx 8325
cx_8325
Cx 8400
cx_8400
7005
7008
7010
7024
7030

CVEs (578)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arubanetworks
1Airwave Glass
Nov 21, 2024
Oct 26, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
1Arubanetworks
6Cx 6200f Firmware
Cx 6300 FirmwareCx 6400 Firmware+3 more
Nov 21, 2024
Sep 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of t...Show more
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the CDP (Cisco Discovery Protocol) process in the switch. This applies to firmware versions prior to 10.04.1000.Show less
1Arubanetworks
6Cx 6200f Firmware
Cx 6300 FirmwareCx 6400 Firmware+3 more
Nov 21, 2024
Sep 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of t...Show more
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the LLDP (Link Layer Discovery Protocol) process in the switch. This applies to firmware versions prior to 10.04.3021.Show less
1Arubanetworks
1Analytics And Location Engine
Nov 21, 2024
Sep 4, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an und...Show more
A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user.Show less
1Arubanetworks
62530 Firmware
2540 Firmware2920 Firmware+3 more
Nov 21, 2024
Aug 26, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Remote Unauthorized Ac...Show more
Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Remote Unauthorized Access in the WebUI.Show less
1Arubanetworks
62530 Firmware
2540 Firmware2920 Firmware+3 more
Nov 21, 2024
Aug 26, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Cross Site Scripting i...Show more
Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Cross Site Scripting in the web UI, leading to injection of code.Show less
1Arubanetworks
1Clearpass Policy Manager
Nov 21, 2024
Jun 3, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, l...Show more
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.Show less
1Arubanetworks
1Clearpass Policy Manager
Nov 21, 2024
Jun 3, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, l...Show more
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.Show less
1Arubanetworks
1Clearpass Policy Manager
Nov 21, 2024
Jun 3, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution...Show more
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.Show less
1Arubanetworks
1Clearpass
Nov 21, 2024
Apr 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this atta...Show more
A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this attack, a possible complete cluster compromise might occur. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.Show less
1Arubanetworks
1Clearpass
Nov 21, 2024
Apr 16, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' se...Show more
A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts. Resolution: Fixed in 6.7.10, 6.8.1, 6.9.0 and higher.Show less
1Arubanetworks
1Clearpass
Nov 21, 2024
Apr 16, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Code Execution in ClearPass. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.
1Arubanetworks
1Clearpass
Nov 21, 2024
Apr 16, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privi...Show more
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.Show less
1Arubanetworks
1Airwave
Nov 21, 2024
Feb 27, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk...Show more
An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component.Show less
1Arubanetworks
1Airwave
Nov 21, 2024
Feb 27, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met,...Show more
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.Show less
1Arubanetworks
72530 10/100 Port Firmware
2530 With Gigt Port Firmware2540 Firmware+4 more
Nov 21, 2024
Feb 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16...Show more
A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007 and 16.10.* before 16.10.0003. The vulnerability allows an attacker to retrieve sensitive system information. This attack can be carried out without user authentication under very specific conditions.Show less
1Arubanetworks
3Airwave
Aruba InstantArubaos
Nov 21, 2024
Jan 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive informatio...Show more
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672Show less
2Arubanetworks
Siemens
4Airwave
Aruba InstantArubaos+1 more
Nov 21, 2024
Jan 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass secu...Show more
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary code.Show less
1Arubanetworks
1Clearpass
Nov 21, 2024
Nov 6, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
2Arubanetworks
Siemens
2Instant
W1750d Firmware
Nov 21, 2024
Oct 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.