Arubanetworks Arubaos vulnerabilities
231 known vulnerabilities affecting arubanetworks/arubaos.
Total CVEs
231
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL46HIGH123MEDIUM58LOW4
Vulnerabilities
Page 12 of 12
CVE-2022-37895P4MEDIUMCVSS 4.9≥ 10.3.0.0, < 10.3.1.12022-10-07
CVE-2022-37895 [MEDIUM] CVE-2022-37895: An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID stri
An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; A
nvd
CVE-2022-37909P4MEDIUMCVSS 5.3≥ 6.5.4.0, < 6.5.4.22≥ 8.4.0.0, < 8.6.0.17+2 more2022-12-12
CVE-2022-37909 [MEDIUM] CWE-200 CVE-2022-37909: Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclo
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.
nvd
CVE-2023-22778P4MEDIUMCVSS 4.8≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22778 [MEDIUM] CWE-79 CVE-2023-22778: A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker
A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
nvd
CVE-2023-22791P4MEDIUMCVSS 4.8≥ 10.3.0.0, ≤ 10.3.1.02023-05-08
CVE-2023-22791 [MEDIUM] CVE-2023-22791: A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network c
A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. The scenarios in which this disclosure of potentially sensitive information can oc
nvd
CVE-2026-23812P4MEDIUMCVSS 4.2≥ 6.5.4.0, ≤ 8.10.0.21≥ 8.11.0.0, ≤ 8.12.0.6+4 more2026-03-04
CVE-2026-23812 [MEDIUM] CWE-300 CVE-2026-23812: A vulnerability has been identified where an attacker connecting to an access point as a standard wi
A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for the interception or modification of traffic intended for the legitimate n
nvd
CVE-2013-2290P4MEDIUMCVSS 4.3v6.2.0.0v6.2.0.1+9 more2013-03-28
CVE-2013-2290 [MEDIUM] CWE-79 CVE-2013-2290: Cross-site scripting (XSS) vulnerability in the dashboard of the ArubaOS Administration WebUI in Aru
Cross-site scripting (XSS) vulnerability in the dashboard of the ArubaOS Administration WebUI in Aruba Networks ArubaOS 6.2.x before 6.2.0.3, 6.1.3.x before 6.1.3.7, 6.1.x-FIPS before 6.1.4.3-FIPS, and 6.1.x-AirGroup before 6.1.3.6-AirGroup, as used by Mobility Controller, allows remote wireless access points to inject arbitrary web script or HTML via
nvd
CVE-2009-3836P4MEDIUMCVSS 6.1v3.1.1v3.3.1.16+5 more2009-11-02
CVE-2009-3836 [MEDIUM] CVE-2009-3836: ArubaOS 3.3.1.x, 3.3.2.x, RN 3.1.x, 3.4.x, and 3.3.2.x-FIPS on the Aruba Mobility Controller allows
ArubaOS 3.3.1.x, 3.3.2.x, RN 3.1.x, 3.4.x, and 3.3.2.x-FIPS on the Aruba Mobility Controller allows remote attackers to cause a denial of service (Access Point crash) via a malformed 802.11 Association Request management frame.
nvd
CVE-2024-25616P4LOWCVSS 3.7≥ 8.10.0.0, < 8.10.0.10≥ 8.11.0.0, < 8.11.2.1+2 more2024-03-05
CVE-2024-25616 [LOW] CVE-2024-25616: Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensit
Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.
nvd
CVE-2026-23810P4LOWCVSS 3.1≥ 6.5.4.0, ≤ 8.10.0.21≥ 8.11.0.0, ≤ 8.12.0.6+4 more2026-03-04
CVE-2026-23810 [LOW] CWE-300 CVE-2026-23810: A vulnerability in the packet processing logic may allow an authenticated attacker to craft and tran
A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Temporal Key (GTK) associated with the victim's BSSID. Successful exploitation may enable GTK-independent tra
nvd
CVE-2026-23811P4LOWCVSS 3.1≥ 6.5.4.0, ≤ 8.10.0.21≥ 8.11.0.0, ≤ 8.12.0.6+4 more2026-03-04
CVE-2026-23811 [LOW] CWE-300 CVE-2026-23811: A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) commu
A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a port-stealing attack - may enable a bi-directional Machine-in-the-Middle (MitM) attack
nvd
CVE-2023-22771P4LOWCVSS 2.4≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22771 [LOW] CWE-613 CVE-2023-22771: An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Succe
An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account
nvd
← Previous12 / 12