VendorsAruba Networks7240xmall versions
Vulnerabilities

Aruba Networks Arubanetworks 7240XM

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2020-24633
There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
Published 2020-12-11 · Modified
10.0EPSS 0.051
CVE-2020-24634
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
Published 2020-12-11 · Modified
10.0EPSS 0.021
CVE-2020-24637
Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this vulnerability this could lead to remote compromise of system integrity by allowing an attacker to load an untrusted or modified kernel in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
Published 2020-12-11 · Modified
9.0EPSS 0.016
CVE-2022-37905
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.008
CVE-2022-37903
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.008
CVE-2022-37904
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.007
CVE-2026-23808
Client Isolation Bypass via GTK Manipulation
Published 2026-03-04 · Analyzed
8.1EPSS 0.003
CVE-2026-23809
MAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic Redirection
Published 2026-03-04 · Analyzed
7.6EPSS 0.003
CVE-2022-37907
A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system. A successful attacker can cause a system hang which can only be resolved via a power cycle of the impacted controller.
Published 2022-11-03 · Modified
7.5EPSS 0.006
CVE-2022-37899
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.017
CVE-2022-37900
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.017
CVE-2022-37901
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.017
CVE-2022-37902
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.017
CVE-2023-22764
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22770
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22769
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22768
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22767
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22766
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22765
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22763
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22762
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2022-37898
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.015
CVE-2023-22773
Authenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion.
Published 2023-02-28 · Modified
7.2EPSS 0.008
CVE-2023-22774
Authenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion.
Published 2023-02-28 · Modified
7.2EPSS 0.008
CVE-2021-37731
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
7.2EPSS 0.003
CVE-2023-22771
Insufficient Session Expiration in ArubaOS Command Line Interface
Published 2023-02-28 · Modified
6.8EPSS 0.004
CVE-2022-37908
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.
Published 2022-11-03 · Modified
6.5EPSS 0.002
CVE-2026-23601
Frame Injection via Shared GTK Allows Traffic Spoofing and Client Compromise
Published 2026-03-04 · Analyzed
5.4EPSS 0.001
CVE-2023-22776
Authenticated Remote Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Read
Published 2023-02-28 · Modified
4.9EPSS 0.007
CVE-2026-23810
Cross-BSSID GTK Re-encryption and Traffic Injection
Published 2026-03-04 · Analyzed
4.3EPSS 0.002
CVE-2026-23811
Unauthorized Bi-Directional Traffic Interception via L2/L3 Manipulation
Published 2026-03-04 · Analyzed
4.3EPSS 0.002
CVE-2026-23812
Security Boundary Bypass via Routing Node Impersonation
Published 2026-03-04 · Analyzed
4.3EPSS 0.001