← Back

Arubanetworks

arubanetworks

578 CVEs • 213 products

Products (213)

Click to collapse
Toggle
Arubaos
arubaos
Sd Wan
sd-wan
Clearpass
clearpass
Airwave
airwave
Instant
instant
Aruba Instant
aruba_instant
Airwave Glass
airwave_glass
Aos Cx
aos-cx
2920 Firmware
2920_firmware
2540 Firmware
2540_firmware
2530 Firmware
2530_firmware
3810 Firmware
3810_firmware
2930 Firmware
2930_firmware
2615 Firmware
2615_firmware
2620 Firmware
2620_firmware
2915 Firmware
2915_firmware
203rp Firmware
203rp_firmware
203r Firmware
203r_firmware
203rp
203r
5400r
3810
2920
2930
2540
Vx 500
vx-500
Vx 1000
vx-1000
Vx 2000
vx-2000
Vx 3000
vx-3000
Vx 5000
vx-5000
Vx 6000
vx-6000
Vx 7000
vx-7000
Vx 9000
vx-9000
Vx 8000
vx-8000
Nx 700
nx-700
Nx 1000
nx-1000
Nx 2000
nx-2000
Nx 3000
nx-3000
Nx 5000
nx-5000
Nx 6000
nx-6000
Nx 7000
nx-7000
Nx 8000
nx-8000
Nx 9000
nx-9000
Nx 10k
nx-10k
Nx 11k
nx-11k
2530
Cx 6200f
cx_6200f
Cx 6300
cx_6300
Cx 6400
cx_6400
Cx 8320
cx_8320
Cx 8325
cx_8325
Cx 8400
cx_8400
7005
7008
7010
7024
7030

CVEs (578)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arubanetworks
1Arubaos
Nov 21, 2024
Sep 13, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could...Show more
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. This vulnerability only affects ArubaOS 8.x.Show less
1Arubanetworks
1Arubaos
Nov 21, 2024
Sep 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger...Show more
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.Show less
1Arubanetworks
1Arubaos
Nov 21, 2024
Sep 13, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit t...Show more
A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a process crash or to execute arbitrary code within the underlying operating system with full system privileges. Such an attack could lead to complete system compromise. The ability to transmit traffic to an IP interface on the mobility controller is required to carry out an attack. The attack leverages the PAPI protocol (UDP port 8211). If the mobility controller is only bridging L2 traffic to an uplink and does not have an IP address that is accessible to the attacker, it cannot be attacked.Show less
2Arubanetworks
Siemens
2Aruba Instant
Scalance W1750d Firmware
Nov 21, 2024
May 10, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker co...Show more
A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.1Show less
2Arubanetworks
Siemens
2Aruba Instant
Scalance W1750d Firmware
Nov 21, 2024
May 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could t...Show more
A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or expose the session cookie for an administrative session. Workaround: Administrators should make sure they log out of the Aruba Instant UI when not actively managing the system, and should use caution clicking links from external sources while logged into the IAP administrative interface. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0Show less
2Arubanetworks
Siemens
2Aruba Instant
Scalance W1750d Firmware
Nov 21, 2024
May 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it crashed. It was discovered that core dumps are stored in a way that u...Show more
If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it crashed. It was discovered that core dumps are stored in a way that unauthenticated users can access them through the Aruba Instant web interface. Core dumps could contain sensitive information such as keys and passwords. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0Show less
2Arubanetworks
Siemens
2Aruba Instant
Scalance W1750d Firmware
Nov 21, 2024
May 10, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this a...Show more
A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. Workaround: None. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0Show less
1Arubanetworks
5203r Firmware
203rp FirmwareAp 300 Series Access Points Firmware+2 more
Nov 21, 2024
Dec 7, 2018
N/A· v4
7.5 HIGH· v3
5.4 MEDIUM· v2
A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP'...Show more
A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986.Show less
1Arubanetworks
1Clearpass Policy Manager
Nov 21, 2024
Dec 7, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute...Show more
Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.Show less
1Arubanetworks
1Clearpass Policy Manager
Nov 21, 2024
Dec 7, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of ClearPass could allow an attacker to compromise the entire cluster through...Show more
A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of ClearPass could allow an attacker to compromise the entire cluster through a specially crafted API call. Network access to the administrative web interface is required to exploit this vulnerability. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.Show less
1Arubanetworks
1Clearpass Policy Manager
Nov 21, 2024
Dec 7, 2018
N/A· v4
9.0 CRITICAL· v3
9.3 HIGH· v2
An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices. The ClearPass OnConnect feature permits administrators to link other network devices into ClearPass for the purpose...Show more
An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices. The ClearPass OnConnect feature permits administrators to link other network devices into ClearPass for the purpose of collecting enhanced information about connected endpoints. A defect in the API could allow a remote attacker to execute arbitrary commands on one of the linked devices. This vulnerability is only applicable if credentials for devices have been supplied to ClearPass under Configuration -> Network -> Devices -> CLI Settings. Resolution: Fixed in 6.7.5 and 6.6.10-hotfix.Show less
1Arubanetworks
1Clearpass Policy Manager
Nov 21, 2024
Dec 7, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An authenticated SQL injection vulnerability in Aruba ClearPass Policy Manager can lead to privilege escalation. All versions of ClearPass are affected by multiple authenticated SQL injection vulnerabilities. In each cas...Show more
An authenticated SQL injection vulnerability in Aruba ClearPass Policy Manager can lead to privilege escalation. All versions of ClearPass are affected by multiple authenticated SQL injection vulnerabilities. In each case, an authenticated administrative user of any type could exploit this vulnerability to gain access to "appadmin" credentials, leading to complete cluster compromise. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.Show less
1Arubanetworks
1Clearpass Policy Manager
Nov 21, 2024
Dec 7, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been disabled may still be able to perform read/write operations on parts of t...Show more
In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been disabled may still be able to perform read/write operations on parts of the XML API. This can lead to unauthorized access to the API and complete compromise of the ClearPass instance if an attacker knows of the existence of these accounts.Show less
1Arubanetworks
1Clearpass
Nov 21, 2024
Aug 6, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrativ...Show more
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface.Show less
1Arubanetworks
1Web Management Portal
Nov 21, 2024
Mar 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
3Arubanetworks
DebianShibboleth
3Clearpass
Debian LinuxXmltooling C
Nov 21, 2024
Feb 27, 2018
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive inf...Show more
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.Show less
1Arubanetworks
1Clearpass
Nov 21, 2024
Jan 8, 2018
N/A· v4
7.1 HIGH· v3
4.9 MEDIUM· v2
Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated...Show more
Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain privileges by advertising independent inner and outer identities within a tunneled EAP method.Show less
3Arubanetworks
SiemensWolfssl
3Instant
Scalance W1750d FirmwareWolfssl
May 13, 2026
Dec 13, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vu...Show more
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."Show less
1Arubanetworks
1Clearpass Policy Manager
May 13, 2026
Oct 16, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code with root privileges via unspecified vectors.
12Arista
ArubanetworksCanonical+9 more
21Arubaos
Debian LinuxDiskstation Manager+18 more
May 13, 2026
Oct 4, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.