Arubanetworks
arubanetworks
578 CVEs • 213 products
Products (213)
Click to collapseToggle
Products (213)
Click to collapse
CVEs (578)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could...Show more |
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger...Show more |
A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit t...Show more |
2Arubanetworks Siemens2Aruba Instant Scalance W1750d FirmwareNov 21, 2024 May 10, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker co...Show more |
2Arubanetworks Siemens2Aruba Instant Scalance W1750d FirmwareNov 21, 2024 May 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could t...Show more |
2Arubanetworks Siemens2Aruba Instant Scalance W1750d FirmwareNov 21, 2024 May 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it crashed. It was discovered that core dumps are stored in a way that u...Show more |
2Arubanetworks Siemens2Aruba Instant Scalance W1750d FirmwareNov 21, 2024 May 10, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this a...Show more |
1Arubanetworks 5203r Firmware 203rp FirmwareAp 300 Series Access Points Firmware+2 moreNov 21, 2024 Dec 7, 2018 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP'...Show more |
1Arubanetworks 1Clearpass Policy Manager Nov 21, 2024 Dec 7, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute...Show more |
1Arubanetworks 1Clearpass Policy Manager Nov 21, 2024 Dec 7, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of ClearPass could allow an attacker to compromise the entire cluster through...Show more |
1Arubanetworks 1Clearpass Policy Manager Nov 21, 2024 Dec 7, 2018 N/A· v4 9.0 CRITICAL· v3 9.3 HIGH· v2 An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices. The ClearPass OnConnect feature permits administrators to link other network devices into ClearPass for the purpose...Show more |
1Arubanetworks 1Clearpass Policy Manager Nov 21, 2024 Dec 7, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An authenticated SQL injection vulnerability in Aruba ClearPass Policy Manager can lead to privilege escalation. All versions of ClearPass are affected by multiple authenticated SQL injection vulnerabilities. In each cas...Show more |
1Arubanetworks 1Clearpass Policy Manager Nov 21, 2024 Dec 7, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been disabled may still be able to perform read/write operations on parts of t...Show more |
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrativ...Show more |
1Arubanetworks 1Web Management Portal Nov 21, 2024 Mar 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an executable extension. |
3Arubanetworks DebianShibboleth3Clearpass Debian LinuxXmltooling CNov 21, 2024 Feb 27, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive inf...Show more |
Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated...Show more |
3Arubanetworks SiemensWolfssl3Instant Scalance W1750d FirmwareWolfsslMay 13, 2026 Dec 13, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vu...Show more |
1Arubanetworks 1Clearpass Policy Manager May 13, 2026 Oct 16, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code with root privileges via unspecified vectors. |
12Arista ArubanetworksCanonical+9 more21Arubaos Debian LinuxDiskstation Manager+18 moreMay 13, 2026 Oct 4, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. |