cbcvebase.

Arubanetworks Arubaos vulnerabilities

231 known vulnerabilities affecting arubanetworks/arubaos.

Total CVEs
231
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL46HIGH123MEDIUM58LOW4

Vulnerabilities

Page 5 of 12
CVE-2008-7023P3CRITICALCVSS 10.0v3.3.1.162009-08-21
CVE-2008-7023 [CRITICAL] CWE-310 CVE-2008-7023: Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same d Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.
nvd
CVE-2026-44852P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44852 [HIGH] CWE-296 CVE-2026-44852: An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based manage An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input validation in the file path parameter. Su
nvd
CVE-2025-37174P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.21≥ 8.11.0.0, < 8.13.1.1+2 more2026-01-13
CVE-2025-37174 [HIGH] CWE-277 CVE-2025-37174: Authenticated arbitrary file write vulnerability exists in the web-based management interface of mob Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating s
nvd
CVE-2022-37903P3HIGHCVSS 8.8≥ 6.5.4.0, < 6.5.4.23≥ 8.4.0.0, < 8.6.0.18+3 more2022-12-12
CVE-2022-37903 [HIGH] CWE-787 CVE-2022-37903: A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with att A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.
nvd
CVE-2023-22761P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22761 [HIGH] CWE-77 CVE-2023-22761: Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management int Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the devic
nvd
CVE-2023-22760P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22760 [HIGH] CWE-77 CVE-2023-22760: Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management int Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the devic
nvd
CVE-2023-22758P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22758 [HIGH] CWE-77 CVE-2023-22758: Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management int Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the devic
nvd
CVE-2023-22759P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22759 [HIGH] CWE-77 CVE-2023-22759: Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management int Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the devic
nvd
CVE-2025-37133P3HIGHCVSS 7.2≥ 8.10.0.0, < 8.10.0.19≥ 8.12.0.0, < 8.12.0.6+3 more2025-10-14
CVE-2025-37133 [HIGH] CWE-77 CVE-2025-37133: An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mob An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2025-37134P3HIGHCVSS 7.2≥ 8.10.0.0, < 8.10.0.19≥ 8.12.0.0, < 8.12.0.6+3 more2025-10-14
CVE-2025-37134 [HIGH] CWE-77 CVE-2025-37134: An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mob An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2026-23820P3HIGHCVSS 7.2≥ 6.4.0.0, ≤ 6.5.4.24≥ 8.4.0.0, < 8.10.0.22+5 more2026-05-12
CVE-2026-23820 [HIGH] CWE-78 CVE-2026-23820: A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant coul A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
nvd
CVE-2025-37132P3HIGHCVSS 7.2≥ 8.10.0.0, < 8.10.0.19≥ 8.12.0.0, < 8.12.0.6+3 more2025-10-14
CVE-2025-37132 [HIGH] CWE-434 CVE-2025-37132: An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-1 An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.
nvd
CVE-2023-45618P3HIGHCVSS 8.2≥ 10.3.0.0, < 10.4.0.3v10.5.0.02023-11-14
CVE-2023-45618 [HIGH] CVE-2023-45618: There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Ar There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity
nvd
CVE-2023-45625P3HIGHCVSS 7.2≥ 10.3.0.0, < 10.4.0.3v10.5.0.02023-11-14
CVE-2023-45625 [HIGH] CWE-77 CVE-2023-45625: Multiple authenticated command injection vulnerabilities exist in the command line interface. Succes Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2022-37900P3HIGHCVSS 7.2≥ 6.5.4.0, < 6.5.4.23≥ 8.4.0.0, < 8.6.0.18+3 more2022-12-12
CVE-2022-37900 [HIGH] CWE-78 CVE-2022-37900: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2022-37899P3HIGHCVSS 7.2≥ 6.5.4.0, < 6.5.4.23≥ 8.4.0.0, < 8.6.0.18+3 more2022-12-12
CVE-2022-37899 [HIGH] CWE-78 CVE-2022-37899: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2022-37902P3HIGHCVSS 7.2≥ 6.5.4.0, < 6.5.4.23≥ 8.4.0.0, < 8.6.0.18+3 more2022-12-12
CVE-2022-37902 [HIGH] CWE-78 CVE-2022-37902: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2022-37901P3HIGHCVSS 7.2≥ 6.5.4.0, < 6.5.4.23≥ 8.4.0.0, < 8.6.0.18+3 more2022-12-12
CVE-2022-37901 [HIGH] CWE-78 CVE-2022-37901: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2025-37176P3HIGHCVSS 7.2≥ 8.6.0.0, < 8.10.0.21≥ 8.11.0.0, < 8.13.1.12026-01-13
CVE-2025-37176 [HIGH] CWE-77 CVE-2025-37176: A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a packag A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted mechanism.
nvd
CVE-2024-25614P3CRITICALCVSS 9.1≥ 8.10.0.0, < 8.10.0.10≥ 8.11.0.0, < 8.11.2.1+2 more2024-03-05
CVE-2024-25614 [CRITICAL] CWE-22 CVE-2024-25614: There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitatio There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to denial-of-service conditions and impact the integrity of the controller.
nvd
Arubanetworks Arubaos vulnerabilities | cvebase