Arubanetworks Instant vulnerabilities

33 known vulnerabilities affecting arubanetworks/instant.

Total CVEs
33
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH9MEDIUM14

Vulnerabilities

Page 2 of 2
CVE-2021-25161MEDIUMCVSS 6.1PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25161 [MEDIUM] CWE-79 CVE-2021-25161: A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Insta
nvd
CVE-2021-25156MEDIUMCVSS 4.9PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25156 [MEDIUM] CVE-2021-25156: A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.
nvd
CVE-2021-25160MEDIUMCVSS 4.9PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25160 [MEDIUM] CVE-2021-25160: A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.
nvd
CVE-2021-25157MEDIUMCVSS 4.9PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25157 [MEDIUM] CVE-2021-25157: A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) p A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.x: 8.7
nvd
CVE-2021-25155MEDIUMCVSS 6.5PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25155 [MEDIUM] CVE-2021-25155: A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.
nvd
CVE-2021-25159MEDIUMCVSS 6.5PoC≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.19+4 more2021-03-30
CVE-2021-25159 [MEDIUM] CVE-2021-25159: A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.
nvd
CVE-2020-24636CRITICALCVSS 9.8≥ 6.5.0.0, < 6.5.4.18≥ 8.3.0.0, < 8.3.0.14+3 more2021-03-29
CVE-2020-24636 [CRITICAL] CWE-78 CVE-2020-24636: A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access P A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.5 and below; Aruba Instant 8.7.x: 8.7.0.0 and below. Aruba has re
nvd
CVE-2021-25143HIGHCVSS 7.5≥ 8.3.0.0, < 8.3.0.13≥ 8.5.0.0, < 8.5.0.10+1 more2021-03-29
CVE-2021-25143 [HIGH] CVE-2021-25143: A remote denial of service (dos) vulnerability was discovered in some Aruba Instant Access Point (IA A remote denial of service (dos) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 8.3.x: 8.3.0.12 and below; Aruba Instant 8.5.x: 8.5.0.9 and below; Aruba Instant 8.6.x: 8.6.0.4 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.
nvd
CVE-2021-25144HIGHCVSS 8.8≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.17+3 more2021-03-29
CVE-2021-25144 [HIGH] CWE-120 CVE-2021-25144: A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) produ A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.16 and below; Aruba Instant 8.3.x: 8.3.0.12 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x: 8.6.0.2 and below. Aruba has released patc
nvd
CVE-2020-24635HIGHCVSS 7.2≥ 6.5.0.0, < 6.5.4.18≥ 8.3.0.0, < 8.3.0.14+3 more2021-03-29
CVE-2020-24635 [HIGH] CWE-78 CVE-2020-24635: A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access P A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x: 8.6.0.5 and below; Aruba Instant 8.7.x: 8.7.0.0 and below. Aruba has releas
nvd
CVE-2019-5317MEDIUMCVSS 6.8≥ 6.4.0.0, ≤ 6.4.4.8-4.2.4.18≥ 6.5.0.0, < 6.5.4.16+4 more2021-03-29
CVE-2019-5317 [MEDIUM] CWE-287 CVE-2019-5317: A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.15 and below; Aruba Instant 8.3.x: 8.3.0.11 and below; Aruba Instant 8.4.x: 8.4.0.5 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x
nvd
CVE-2018-16417HIGHCVSS 7.5≥ 4.0.0.0, < 4.2.4.12≥ 6.5.0.0, < 6.5.4.11+2 more2019-10-30
CVE-2018-16417 [HIGH] CWE-77 CVE-2018-16417: Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8. Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.
nvd
CVE-2017-13099MEDIUMCVSS 5.9fixed in 6.5.4.62017-12-13
CVE-2017-13099 [MEDIUM] CWE-203 CVE-2017-13099: wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite usin wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT."
nvd