Arubanetworks Arubaos vulnerabilities
231 known vulnerabilities affecting arubanetworks/arubaos.
Total CVEs
231
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL46HIGH123MEDIUM58LOW4
Vulnerabilities
Page 6 of 12
CVE-2023-45617P3HIGHCVSS 8.2≥ 10.3.0.0, < 10.4.0.3v10.5.0.02023-11-14
CVE-2023-45617 [HIGH] CVE-2023-45617: There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's acces
There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the acce
nvd
CVE-2023-45619P3HIGHCVSS 8.2≥ 10.3.0.0, < 10.4.0.3v10.5.0.02023-11-14
CVE-2023-45619 [HIGH] CVE-2023-45619: There is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's acce
There is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the acces
nvd
CVE-2021-37717P3HIGHCVSS 7.2≥ 8.3.0.0, < 8.3.0.16≥ 8.5.0.0, < 8.5.0.12+2 more2021-09-07
CVE-2021-37717 [HIGH] CWE-77 CVE-2021-37717: A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gatew
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
nvd
CVE-2021-37718P3HIGHCVSS 7.2≥ 8.3.0.0, < 8.3.0.16≥ 8.5.0.0, < 8.5.0.12+2 more2021-09-07
CVE-2021-37718 [HIGH] CWE-77 CVE-2021-37718: A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gatew
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
nvd
CVE-2024-31475P3HIGHCVSS 8.2≥ 10.3.0.0, < 10.4.1.1≥ 10.5.0.0, < 10.5.1.12024-05-14
CVE-2024-31475 [HIGH] CWE-463 CVE-2024-31475: There is an arbitrary file deletion vulnerability in the Central Communications service accessed by
There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact t
nvd
CVE-2023-35972P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.6.0.21≥ 8.7.0.0, < 8.10.0.7+2 more2023-07-05
CVE-2023-35972 [HIGH] CWE-77 CVE-2023-35972: An authenticated remote command injection vulnerability exists in the ArubaOS web-based management i
An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the devic
nvd
CVE-2025-27083P3HIGHCVSS 7.2≥ 8.10.0.0, < 8.10.0.16≥ 8.12.0.0, < 8.12.0.4+2 more2025-04-08
CVE-2025-27083 [HIGH] CWE-77 CVE-2025-27083: Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility
Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2025-27082P3HIGHCVSS 7.2≥ 8.10.0.0, < 8.10.0.16≥ 8.12.0.0, < 8.12.0.4+2 more2025-04-08
CVE-2025-27082 [HIGH] CWE-434 CVE-2025-27082: Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10
Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system.
nvd
CVE-2021-37720P3HIGHCVSS 7.2≥ 6.4.4.0, < 6.4.4.25≥ 6.5.4.0, < 6.5.4.20+4 more2021-09-07
CVE-2021-37720 [HIGH] CWE-77 CVE-2021-37720: A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gatew
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnera
nvd
CVE-2021-37721P3HIGHCVSS 7.2≥ 6.4.4.0, < 6.4.4.25≥ 6.5.4.0, < 6.5.4.20+4 more2021-09-07
CVE-2021-37721 [HIGH] CWE-77 CVE-2021-37721: A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gatew
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnera
nvd
CVE-2021-37722P3HIGHCVSS 7.2≥ 6.4.4.0, < 6.4.4.25≥ 6.5.4.0, < 6.5.4.20+4 more2021-09-07
CVE-2021-37722 [HIGH] CWE-77 CVE-2021-37722: A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gatew
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnera
nvd
CVE-2024-31474P3HIGHCVSS 8.2≥ 10.3.0.0, < 10.4.1.1≥ 10.5.0.0, < 10.5.1.12024-05-14
CVE-2024-31474 [HIGH] CWE-463 CVE-2024-31474: There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Acces
There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of th
nvd
CVE-2021-37719P3HIGHCVSS 7.2≥ 6.4.4.0, < 6.4.4.25≥ 6.5.4.0, < 6.5.4.20+4 more2021-09-07
CVE-2021-37719 [HIGH] CWE-77 CVE-2021-37719: A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gatew
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnera
nvd
CVE-2022-37898P3HIGHCVSS 7.2≥ 6.5.4.0, < 6.5.4.23≥ 8.4.0.0, < 8.6.0.18+3 more2022-12-12
CVE-2022-37898 [HIGH] CWE-78 CVE-2022-37898: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2024-1356P3HIGHCVSS 7.2≥ 8.10.0.0, ≤ 8.10.0.9≥ 8.11.0.0, ≤ 8.11.2.0+2 more2024-03-05
CVE-2024-1356 [HIGH] CWE-77 CVE-2024-1356: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2024-25613P3HIGHCVSS 7.2≥ 8.10.0.0, < 8.10.0.10≥ 8.11.0.0, < 8.11.2.1+2 more2024-03-05
CVE-2024-25613 [HIGH] CWE-77 CVE-2024-25613: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2024-25611P3HIGHCVSS 7.2≥ 8.10.0.0, < 8.10.0.10≥ 8.11.0.0, < 8.11.2.1+2 more2024-03-05
CVE-2024-25611 [HIGH] CWE-77 CVE-2024-25611: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2024-25612P3HIGHCVSS 7.2≥ 8.10.0.0, < 8.10.0.10≥ 8.11.0.0, < 8.11.2.1+2 more2024-03-05
CVE-2024-25612 [HIGH] CWE-77 CVE-2024-25612: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2025-37169P3HIGHCVSS 7.2≥ 10.3.0.0, < 10.4.1.10≥ 10.5.0.0, < 10.7.2.22026-01-13
CVE-2025-37169 [HIGH] CWE-787 CVE-2025-37169: A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gat
A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system.
nvd
CVE-2022-37906P3HIGHCVSS 8.1≥ 6.5.4.0, < 6.5.4.22≥ 8.4.0.0, < 8.6.0.17+2 more2022-12-12
CVE-2022-37906 [HIGH] CWE-22 CVE-2022-37906: An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successf
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.
nvd