cbcvebase.

Arubanetworks Instant vulnerabilities

33 known vulnerabilities affecting arubanetworks/instant.

Total CVEs
33
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH9MEDIUM14

Vulnerabilities

Page 1 of 2
CVE-2021-25162P2HIGHCVSS 8.1PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25162 [HIGH] CWE-78 CVE-2021-25162: A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access P A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba I
nvd
CVE-2021-25158P3MEDIUMCVSS 5.9PoC≥ 6.5.0.0, < 6.5.4.19≥ 8.3.0.0, < 8.3.0.15+3 more2021-03-30
CVE-2021-25158 [MEDIUM] CWE-362 CVE-2021-25158: A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) p A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patche
nvd
CVE-2021-25156P3MEDIUMCVSS 4.9PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25156 [MEDIUM] CVE-2021-25156: A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.
nvd
CVE-2021-25155P3MEDIUMCVSS 6.5PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25155 [MEDIUM] CVE-2021-25155: A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.
nvd
CVE-2021-25159P3MEDIUMCVSS 6.5PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25159 [MEDIUM] CVE-2021-25159: A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.
nvd
CVE-2021-25161P3MEDIUMCVSS 6.1PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25161 [MEDIUM] CWE-79 CVE-2021-25161: A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Insta
nvd
CVE-2022-37889P2CRITICALCVSS 9.8≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37889 [CRITICAL] CWE-120 CVE-2022-37889: There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthe There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a
nvd
CVE-2022-37887P2CRITICALCVSS 9.8≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37887 [CRITICAL] CWE-120 CVE-2022-37887: There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthe There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a
nvd
CVE-2022-37888P2CRITICALCVSS 9.8≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-06
CVE-2022-37888 [CRITICAL] CWE-120 CVE-2022-37888: There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthe There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a
nvd
CVE-2022-37886P2CRITICALCVSS 9.8≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37886 [CRITICAL] CWE-120 CVE-2022-37886: There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthe There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a
nvd
CVE-2022-37885P2CRITICALCVSS 9.8≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37885 [CRITICAL] CWE-120 CVE-2022-37885: There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthe There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a
nvd
CVE-2022-37891P2CRITICALCVSS 9.8≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37891 [CRITICAL] CWE-120 CVE-2022-37891: Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.
nvd
CVE-2022-37890P2CRITICALCVSS 9.8≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37890 [CRITICAL] CWE-120 CVE-2022-37890: Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.
nvd
CVE-2020-24636P2CRITICALCVSS 9.8≥ 6.5.0.0, < 6.5.4.18≥ 8.3.0.0, < 8.3.0.14+3 more2021-03-29
CVE-2020-24636 [CRITICAL] CWE-78 CVE-2020-24636: A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access P A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.5 and below; Aruba Instant 8.7.x: 8.7.0.0 and below. Aruba has re
nvd
CVE-2021-25157P3MEDIUMCVSS 4.9PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25157 [MEDIUM] CVE-2021-25157: A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) p A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.x: 8.7
nvd
CVE-2021-25160P3MEDIUMCVSS 4.9PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25160 [MEDIUM] CVE-2021-25160: A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.
nvd
CVE-2021-25150P2HIGHCVSS 8.8≥ 6.5.0.0, < 6.5.4.18≥ 8.3.0.0, < 8.3.0.14+2 more2021-03-30
CVE-2021-25150 [HIGH] CWE-78 CVE-2021-25150: A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access P A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.4 and below. Aruba has released patches for Aruba Instant that addres
nvd
CVE-2019-5319P3CRITICALCVSS 9.8≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.17≥ 6.5.0.0, < 6.5.4.17+3 more2021-03-30
CVE-2019-5319 [CRITICAL] CWE-120 CVE-2019-5319: A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) produ A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.16 and below; Aruba Instant 8.3.x: 8.3.0.12 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x: 8.6.0.2 and below. Aruba has released pa
nvd
CVE-2021-25149P3CRITICALCVSS 9.8≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.17+3 more2021-03-30
CVE-2021-25149 [CRITICAL] CWE-120 CVE-2021-25149: A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) produ A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.16 and below; Aruba Instant 8.3.x: 8.3.0.12 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x: 8.6.0.2 and below. Aruba has released
nvd
CVE-2021-25144P3HIGHCVSS 8.8≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.17+3 more2021-03-29
CVE-2021-25144 [HIGH] CWE-120 CVE-2021-25144: A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) produ A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.16 and below; Aruba Instant 8.3.x: 8.3.0.12 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x: 8.6.0.2 and below. Aruba has released patc
nvd