Arubanetworks Instant vulnerabilities
33 known vulnerabilities affecting arubanetworks/instant.
Total CVEs
33
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH9MEDIUM14
Vulnerabilities
Page 2 of 2
CVE-2018-16417P3HIGHCVSS 7.5≥ 4.0.0.0, < 4.2.4.12≥ 6.5.0.0, < 6.5.4.11+2 more2019-10-30
CVE-2018-16417 [HIGH] CWE-77 CVE-2018-16417: Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.
Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.
nvd
CVE-2021-25146P3HIGHCVSS 7.2≥ 6.5.0.0, < 6.5.4.18≥ 8.3.0.0, < 8.3.0.14+3 more2021-03-30
CVE-2021-25146 [HIGH] CWE-78 CVE-2021-25146: A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access P
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.5 and below; Aruba Instant 8.7.x: 8.7.0.0 and below. Aruba has releas
nvd
CVE-2020-24635P3HIGHCVSS 7.2≥ 6.5.0.0, < 6.5.4.18≥ 8.3.0.0, < 8.3.0.14+3 more2021-03-29
CVE-2020-24635 [HIGH] CWE-78 CVE-2020-24635: A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access P
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.5 and below; Aruba Instant 8.7.x: 8.7.0.0 and below. Aruba has releas
nvd
CVE-2022-37893P3HIGHCVSS 7.8≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37893 [HIGH] CWE-78 CVE-2022-37893: An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 comman
An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.
nvd
CVE-2017-13099P3MEDIUMCVSS 5.9fixed in 6.5.4.62017-12-13
CVE-2017-13099 [MEDIUM] CWE-203 CVE-2017-13099: wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite usin
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."
nvd
CVE-2021-25148P3HIGHCVSS 8.1≥ 6.5.0.0, < 6.5.4.18≥ 8.3.0.0, < 8.3.0.14+2 more2021-03-30
CVE-2021-25148 [HIGH] CVE-2021-25148: A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.4 and below. Aruba has released patches for Aruba Instant that address this secu
nvd
CVE-2021-25143P3HIGHCVSS 7.5≥ 8.3.0.0, < 8.3.0.13≥ 8.5.0.0, < 8.5.0.10+1 more2021-03-29
CVE-2021-25143 [HIGH] CVE-2021-25143: A remote denial of service (dos) vulnerability was discovered in some Aruba Instant Access Point (IA
A remote denial of service (dos) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 8.3.x: 8.3.0.12 and below; Aruba Instant 8.5.x: 8.5.0.9 and below; Aruba Instant 8.6.x: 8.6.0.4 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.
nvd
CVE-2021-25145P4MEDIUMCVSS 6.5≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25145 [MEDIUM] CVE-2021-25145: A remote unauthorized disclosure of information vulnerability was discovered in some Aruba Instant A
A remote unauthorized disclosure of information vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.5 and below; Aruba
nvd
CVE-2019-5317P4MEDIUMCVSS 6.8≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.16+4 more2021-03-29
CVE-2019-5317 [MEDIUM] CWE-287 CVE-2019-5317: A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP)
A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.15 and below; Aruba Instant 8.3.x: 8.3.0.11 and below; Aruba Instant 8.4.x: 8.4.0.5 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x
nvd
CVE-2022-37894P4MEDIUMCVSS 6.5≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37894 [MEDIUM] CVE-2022-37894: An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID stri
An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; A
nvd
CVE-2022-37896P4MEDIUMCVSS 6.1≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37896 [MEDIUM] CWE-79 CVE-2022-37896: A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote
A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface of Aruba Inst
nvd
CVE-2022-37892P4MEDIUMCVSS 5.4≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37892 [MEDIUM] CWE-79 CVE-2022-37892: A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauth
A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interfac
nvd
CVE-2022-37895P4MEDIUMCVSS 4.9≥ 6.4.0.0, < 6.4.4.8-4.2.4.21≥ 6.5.0.0, < 6.5.4.24+3 more2022-10-07
CVE-2022-37895 [MEDIUM] CVE-2022-37895: An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID stri
An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; A
nvd
← Previous2 / 2