cbcvebase.

Arubanetworks Arubaos vulnerabilities

231 known vulnerabilities affecting arubanetworks/arubaos.

Total CVEs
231
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL46HIGH123MEDIUM58LOW4

Vulnerabilities

Page 7 of 12
CVE-2021-37723P3HIGHCVSS 7.2≥ 8.3.0.0, < 8.3.0.16≥ 8.5.0.0, < 8.5.0.12+2 more2021-09-07
CVE-2021-37723 [HIGH] CWE-77 CVE-2021-37723: A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released patches for ArubaOS that address this security vulnerability.
nvd
CVE-2021-37724P3HIGHCVSS 7.2≥ 8.3.0.0, < 8.3.0.16≥ 8.5.0.0, < 8.5.0.12+2 more2021-09-07
CVE-2021-37724 [HIGH] CWE-77 CVE-2021-37724: A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released patches for ArubaOS that address this security vulnerability.
nvd
CVE-2023-35975P3HIGHCVSS 8.1≥ 6.5.4.0, < 8.6.0.21≥ 8.7.0.0, < 8.10.0.7+2 more2023-07-05
CVE-2023-35975 [HIGH] CWE-22 CVE-2023-35975: An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successf An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.
nvd
CVE-2026-23808P3HIGHCVSS 8.1≥ 6.5.4.0, ≤ 8.10.0.21≥ 8.11.0.0, ≤ 8.12.0.6+4 more2026-03-04
CVE-2026-23808 [HIGH] CWE-94 CVE-2026-23808: A vulnerability has been identified in a standardized wireless roaming protocol that could enable a A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could allow a remote malicious actor to perform unauthorized frame injection, bypass client isolation, interfere w
nvd
CVE-2023-22769P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22769 [HIGH] CWE-77 CVE-2023-22769: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-22770P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22770 [HIGH] CWE-77 CVE-2023-22770: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-22766P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22766 [HIGH] CWE-77 CVE-2023-22766: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-22765P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22765 [HIGH] CWE-77 CVE-2023-22765: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-22768P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22768 [HIGH] CWE-77 CVE-2023-22768: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-22762P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22762 [HIGH] CWE-77 CVE-2023-22762: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-22767P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22767 [HIGH] CWE-77 CVE-2023-22767: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-22764P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22764 [HIGH] CWE-77 CVE-2023-22764: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-22763P3HIGHCVSS 7.2≥ 8.6.0.0, ≤ 8.6.0.19≥ 8.10.0.0, ≤ 8.10.0.4+1 more2023-03-01
CVE-2023-22763 [HIGH] CWE-77 CVE-2023-22763: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-35974P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.6.0.21≥ 8.7.0.0, < 8.10.0.7+2 more2023-07-05
CVE-2023-35974 [HIGH] CWE-77 CVE-2023-35974: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2023-35973P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.6.0.21≥ 8.7.0.0, < 8.10.0.7+2 more2023-07-05
CVE-2023-35973 [HIGH] CWE-77 CVE-2023-35973: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Success Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2026-23826P3HIGHCVSS 7.5≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+1 more2026-05-12
CVE-2026-23826 [HIGH] CWE-770 CVE-2026-23826: A vulnerability in a network management service of AOS-8 Operating System could allow an unauthentic A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition. Successful exploitation could cause the affected service process to terminate
nvd
CVE-2026-23824P3HIGHCVSS 7.5≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-23824 [HIGH] CWE-400 CVE-2026-23824: Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An una Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical system process, resulting in a denial
nvd
CVE-2026-23825P3HIGHCVSS 7.5≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-23825 [HIGH] CWE-20 CVE-2026-23825: Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An una Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical system process, resulting in a denial-
nvd
CVE-2019-5315P3HIGHCVSS 7.2≥ 8.0.0.0, < 8.3.0.02019-09-13
CVE-2019-5315 [HIGH] CWE-78 CVE-2019-5315: A command injection vulnerability is present in the web management interface of ArubaOS that permits A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. This vulnerability only affects
nvd
CVE-2022-37893P3HIGHCVSS 7.8≥ 10.3.0.0, < 10.3.1.12022-10-07
CVE-2022-37893 [HIGH] CWE-78 CVE-2022-37893: An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 comman An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.
nvd
Arubanetworks Arubaos vulnerabilities | cvebase