Arubanetworks
arubanetworks
635 CVEs • 213 products
Products (213)
Click to collapseToggle
Products (213)
Click to collapse
CVEs (635)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Arubanetworks 1Analytics And Location Engine Jun 17, 2026 Sep 4, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an und...Show more |
1Arubanetworks 62530 Firmware 2540 Firmware2920 Firmware+3 moreJun 17, 2026 Aug 26, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Remote Unauthorized Ac...Show more |
1Arubanetworks 62530 Firmware 2540 Firmware2920 Firmware+3 moreJun 17, 2026 Aug 26, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Cross Site Scripting i...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jun 3, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, l...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jun 3, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, l...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jun 3, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution...Show more |
A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this atta...Show more |
A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' se...Show more |
A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Code Execution in ClearPass. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher. |
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privi...Show more |
An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk...Show more |
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met,...Show more |
1Arubanetworks 72530 10/100 Port Firmware 2530 With Gigt Port Firmware2540 Firmware+4 moreJun 17, 2026 Feb 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16...Show more |
1Arubanetworks 3Airwave Aruba InstantArubaosNov 21, 2024 Jan 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive informatio...Show more |
2Arubanetworks Siemens4Airwave Aruba InstantArubaos+1 moreNov 21, 2024 Jan 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass secu...Show more |
Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials. |
2Arubanetworks Siemens2Instant W1750d FirmwareNov 21, 2024 Oct 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection. |
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could...Show more |
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger...Show more |
A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit t...Show more |