VendorsAruba Networksarubaosall versions
Vulnerabilities

Aruba Networks ArubaOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

233CVEs
CVE-2024-31474
There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point
Published 2024-05-14 · Modified
8.2EPSS 0.004
CVE-2024-31475
There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point.
Published 2024-05-14 · Modified
8.2EPSS 0.004
CVE-2022-37906
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.
Published 2022-11-03 · Modified
8.1EPSS 0.008
CVE-2023-35975
Authenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion
Published 2023-07-05 · Modified
8.1EPSS 0.007
CVE-2026-23808
Client Isolation Bypass via GTK Manipulation
Published 2026-03-04 · Analyzed
8.1EPSS 0.003
CVE-2023-38484
Multiple Buffer Overflow Vulnerabilities in BIOS Implementation of 9200 and 9000 Series Controllers and Gateways
Published 2023-09-06 · Modified
8.0EPSS 0.004
CVE-2023-38485
Multiple Buffer Overflow Vulnerabilities in BIOS Implementation of 9200 and 9000 Series Controllers and Gateways
Published 2023-09-06 · Modified
8.0EPSS 0.004
CVE-2008-7095
The SNMP daemon in ArubaOS 3.3.2.6 in Aruba Mobility Controller does not restrict SNMP access, which allows remote attackers to (1) read all SNMP community strings via SNMP-COMMUNITY-MIB::snmpCommunityName (1.3.6.1.6.3.18.1.1.1.2) or SNMP-VIEW-BASED-ACM-MIB::vacmGroupName (1.3.6.1.6.3.16.1.2.1.3) with knowledge of one community string, and (2) read SNMPv3 user names via SNMP-USER-BASED-SM-MIB or SNMP-VIEW-BASED-ACM-MIB.
Published 2009-08-27 · Modified
7.8EPSS 0.014
CVE-2022-37893
An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.
Published 2022-10-07 · Modified
7.8EPSS 0.008
CVE-2023-38486
Hardware Root of Trust Bypass in 9200 and 9000 Series Controllers and Gateways
Published 2023-09-06 · Modified
7.7EPSS 0.003
CVE-2026-23809
MAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic Redirection
Published 2026-03-04 · Analyzed
7.6EPSS 0.003
CVE-2016-2032
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672
Published 2020-01-31 · Modified
7.5EPSS 0.027
CVE-2014-7299
Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authentication, and obtain potentially sensitive information or add guest accounts, via an SSH session.
Published 2014-10-08 · Modified
7.5EPSS 0.021
CVE-2023-45620
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
CVE-2023-45621
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
CVE-2023-45622
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
CVE-2023-45623
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
CVE-2023-45624
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
CVE-2023-22787
Unauthenticated Denial of Service (DoS) in Aruba InstantOS or ArubaOS 10 Service Accessed via the PAPI Protocol
Published 2023-05-08 · Modified
7.5EPSS 0.008
CVE-2018-7080
A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986.
Published 2018-12-07 · Modified
7.5EPSS 0.006
CVE-2023-35979
Unauthenticated Buffer Overflow Vulnerability in ArubaOS Web-Based Management Interface
Published 2023-07-05 · Modified
7.5EPSS 0.006
CVE-2024-33515
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected service.
Published 2024-05-01 · Analyzed
7.5EPSS 0.006
CVE-2024-33514
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected service.
Published 2024-05-01 · Analyzed
7.5EPSS 0.006
CVE-2024-33517
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
Published 2024-05-01 · Analyzed
7.5EPSS 0.006
CVE-2024-33516
An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.
Published 2024-05-01 · Analyzed
7.5EPSS 0.006
CVE-2022-37907
A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system. A successful attacker can cause a system hang which can only be resolved via a power cycle of the impacted controller.
Published 2022-11-03 · Modified
7.5EPSS 0.006
CVE-2024-31481
Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.
Published 2024-05-14 · Modified
7.5EPSS 0.006
CVE-2024-31479
Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.
Published 2024-05-14 · Modified
7.5EPSS 0.006
CVE-2024-31480
Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.
Published 2024-05-14 · Modified
7.5EPSS 0.006
CVE-2024-31478
Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilites result in the ability to interrupt the normal operation of the affected Access Point.
Published 2024-05-14 · Modified
7.5EPSS 0.006
CVE-2024-31482
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected Access Point.
Published 2024-05-14 · Modified
7.5EPSS 0.005
CVE-2026-23827
Unauthenticated Remote Code Execution via Heap Buffer Overflow in Network Management Service
Published 2026-05-12 · Analyzed
7.5EPSS 0.005
CVE-2026-23826
Unauthenticated Denial of Service in AOS-8 Network Management Service
Published 2026-05-12 · Analyzed
7.5EPSS 0.004
CVE-2025-37161
Unauthenticated Remote Denial-of-Service (DoS) Vulnerability in Web Management Interface
Published 2025-11-18 · Analyzed
7.5EPSS 0.004
CVE-2025-37178
Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating System
Published 2026-01-13 · Analyzed
7.5EPSS 0.004
CVE-2026-23825
Unauthenticated Denial-of-Service via Crafted Messages in a Network Protocol Handling Component
Published 2026-05-12 · Analyzed
7.5EPSS 0.003
CVE-2026-23824
Unauthenticated Denial-of-Service via Crafted Messages in a Network Protocol Handling Component
Published 2026-05-12 · Analyzed
7.5EPSS 0.003
CVE-2023-45625
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2023-11-14 · Modified
7.2EPSS 0.018
CVE-2022-37899
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.017
CVE-2022-37900
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.017
← Prev3 / 6Next →