VendorsAruba Networksarubaosall versions
Vulnerabilities

Aruba Networks ArubaOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

233CVEs
CVE-2023-22754
Unauthenticated Buffer Overflow Vulnerabilities in ArubaOS Processes
Published 2023-02-28 · Modified
9.8EPSS 0.011
CVE-2024-42393
Unauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the Soft AP Daemon Service Accessed by the PAPI Protocol
Published 2024-08-06 · Analyzed
9.8EPSS 0.006
CVE-2024-42394
Unauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the Soft AP Daemon Service Accessed by the PAPI Protocol
Published 2024-08-06 · Analyzed
9.8EPSS 0.006
CVE-2024-42395
Unauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the AP Certificate Management Service Accessed by the PAPI Protocol
Published 2024-08-06 · Analyzed
9.8EPSS 0.004
CVE-2024-25614
There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to denial-of-service conditions and impact the integrity of the controller.
Published 2024-03-05 · Analyzed
9.1EPSS 0.005
CVE-2025-37168
Unauthenticated Arbitrary File Deletion Vulnerability in AOS-8 Operating System
Published 2026-01-13 · Analyzed
9.1EPSS 0.004
CVE-2021-37718
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37721
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37723
A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released patches for ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37724
A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released patches for ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37722
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37720
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37717
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.031
CVE-2021-37719
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
9.0EPSS 0.029
CVE-2008-2273
Unspecified vulnerability in the TACACS authentication component in Aruba Mobility Controller 3.1.x, 3.2.x, and 3.3.x allows remote authenticated users to gain privileges via unknown vectors.
Published 2008-05-16 · Modified
9.0EPSS 0.023
CVE-2019-5315
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. This vulnerability only affects ArubaOS 8.x.
Published 2019-09-13 · Modified
9.0EPSS 0.022
CVE-2020-24637
Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this vulnerability this could lead to remote compromise of system integrity by allowing an attacker to load an untrusted or modified kernel in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.
Published 2020-12-11 · Modified
9.0EPSS 0.016
CVE-2023-22790
Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface
Published 2023-05-08 · Modified
8.8EPSS 0.016
CVE-2023-22788
Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface
Published 2023-05-08 · Modified
8.8EPSS 0.016
CVE-2022-37912
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.016
CVE-2023-22789
Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface
Published 2023-05-08 · Modified
8.8EPSS 0.016
CVE-2024-31476
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
8.8EPSS 0.015
CVE-2024-31477
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
8.8EPSS 0.015
CVE-2026-44871
Authenticated Command Injection Vulnerabilities in Command Line Interface (CLI) Service Accessed by PAPI Protocol of AOS-8 and AOS-10 Operating Systems
Published 2026-05-12 · Analyzed
8.8EPSS 0.014
CVE-2026-44870
Authenticated Command Injection Vulnerabilities in Command Line Interface (CLI) Service Accessed by PAPI Protocol of AOS-8 and AOS-10 Operating Systems
Published 2026-05-12 · Analyzed
8.8EPSS 0.014
CVE-2026-44866
Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Published 2026-05-12 · Analyzed
8.8EPSS 0.014
CVE-2026-44869
Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Published 2026-05-12 · Analyzed
8.8EPSS 0.014
CVE-2026-44867
Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Published 2026-05-12 · Analyzed
8.8EPSS 0.014
CVE-2026-44868
Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Published 2026-05-12 · Analyzed
8.8EPSS 0.014
CVE-2025-37162
Authenticated Command Injection Vulnerability Leading to Arbitrary Remote Command Execution
Published 2025-11-18 · Analyzed
8.8EPSS 0.009
CVE-2022-37905
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.008
CVE-2022-37903
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.008
CVE-2022-37904
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Published 2022-11-03 · Modified
8.8EPSS 0.007
CVE-2023-35971
Unauthenticated Stored Cross-Site Scripting (XSS) in ArubaOS Web-based Management Interface
Published 2023-07-05 · Modified
8.8EPSS 0.006
CVE-2021-37725
A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.8.0.1, 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
8.8EPSS 0.004
CVE-2026-23819
Error in SSID Processing allows Stored XSS in Web Management Interface
Published 2026-05-12 · Analyzed
8.8EPSS 0.003
CVE-2021-37728
A remote path traversal vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.8.0.1, 8.7.1.4, 8.6.0.11, 8.5.0.13. Aruba has released patches for ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
8.5EPSS 0.011
CVE-2023-45618
There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Published 2023-11-14 · Modified
8.2EPSS 0.007
CVE-2023-45617
There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Published 2023-11-14 · Modified
8.2EPSS 0.007
CVE-2023-45619
There is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Published 2023-11-14 · Modified
8.2EPSS 0.007
← Prev2 / 6Next →