VendorsAruba Networksarubaosall versions
Vulnerabilities

Aruba Networks ArubaOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

233CVEs
CVE-2026-44855
Authenticated Stack-Based Buffer Overflow in PAPI Services
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-44856
Authenticated Stack-Based Buffer Overflow in PAPI Services
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-44858
Authenticated Stack-Based Buffer Overflow in PAPI Services
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-44859
Authenticated Stack-Based Buffer Overflow in PAPI Services
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-23821
Inconsistent input filtering allows Authenticated Command Injection in AOS-10 CLI
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-44852
Authenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management Interface
Published 2026-05-12 · Modified
7.2EPSS 0.006
CVE-2026-44864
Authenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating Systems
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-44862
Authenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating Systems
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-44863
Authenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating Systems
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-44860
Authenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating Systems
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-44861
Authenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating Systems
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-23820
Inconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and AOS-10 CLI
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2025-37169
Stack Overflow Vulnerability in AOS-10 Web-Based Management Interface
Published 2026-01-13 · Modified
7.2EPSS 0.006
CVE-2025-37174
Authenticated Arbitrary File Write Vulnerability in AOS 10 and AOS-8 Web-Based Management Interface
Published 2026-01-13 · Analyzed
7.2EPSS 0.006
CVE-2025-27082
Authenticated Remote Code Execution Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File Write
Published 2025-04-08 · Analyzed
7.2EPSS 0.005
CVE-2025-37132
Authenticated Remote Code Execution Vulnerability in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File Write
Published 2025-10-14 · Analyzed
7.2EPSS 0.005
CVE-2025-37175
Authenticated Arbitrary File Upload Vulnerability in AOS-10 or AOS-8 Web-Based Management Interface
Published 2026-01-13 · Analyzed
7.2EPSS 0.005
CVE-2025-37173
Improper Input Handling Vulnerability in Authenticated Configuration API Endpoint (AOS-10/AOS-8 Web UI)
Published 2026-01-13 · Analyzed
7.2EPSS 0.004
CVE-2021-37731
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
7.2EPSS 0.003
CVE-2019-5318
A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x: all versions prior to 8.8.0.0. Aruba has released patches for ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
7.1EPSS 0.004
CVE-2023-22771
Insufficient Session Expiration in ArubaOS Command Line Interface
Published 2023-02-28 · Modified
6.8EPSS 0.004
CVE-2021-37729
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.3, 8.6.0.9, 8.5.0.12, 8.3.0.16, 6.5.4.19, 6.4.4.25. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
6.5EPSS 0.010
CVE-2023-45627
An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
6.5EPSS 0.008
CVE-2023-22772
Authenticated Path Traversal in ArubaOS Web-based Management Interface Allows for Arbitrary File Deletion
Published 2023-02-28 · Modified
6.5EPSS 0.007
CVE-2022-37910
A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system.
Published 2022-11-03 · Modified
6.5EPSS 0.006
CVE-2023-22777
Authenticated Information Disclosure in ArubaOS Web-based Management Interface
Published 2023-02-28 · Modified
6.5EPSS 0.006
CVE-2023-22775
Authenticated Sensitive Information Disclosure in ArubaOS Command Line Interface
Published 2023-02-28 · Modified
6.5EPSS 0.006
CVE-2023-35976
Authenticated Sensitive Information Disclosure in ArubaOS Command Line Interface
Published 2023-07-05 · Modified
6.5EPSS 0.006
CVE-2023-35977
Authenticated Sensitive Information Disclosure in ArubaOS Command Line Interface
Published 2023-07-05 · Modified
6.5EPSS 0.006
CVE-2022-37894
An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.
Published 2022-10-07 · Modified
6.5EPSS 0.004
CVE-2024-31483
An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.
Published 2024-05-14 · Modified
6.5EPSS 0.004
CVE-2025-37135
Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)
Published 2025-10-14 · Analyzed
6.5EPSS 0.004
CVE-2025-37136
Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)
Published 2025-10-14 · Analyzed
6.5EPSS 0.004
CVE-2025-37137
Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)
Published 2025-10-14 · Analyzed
6.5EPSS 0.004
CVE-2025-37177
Authenticated Arbitrary File Deletion Vulnerability in AOS-10 or AOS-8 Command Line Interface (CLI)
Published 2026-01-13 · Analyzed
6.5EPSS 0.004
CVE-2022-37908
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.
Published 2022-11-03 · Modified
6.5EPSS 0.002
CVE-2025-37138
Authenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface (Physical Access Required)
Published 2025-10-14 · Analyzed
6.2EPSS 0.007
CVE-2009-3836
ArubaOS 3.3.1.x, 3.3.2.x, RN 3.1.x, 3.4.x, and 3.3.2.x-FIPS on the Aruba Mobility Controller allows remote attackers to cause a denial of service (Access Point crash) via a malformed 802.11 Association Request management frame.
Published 2009-11-02 · Modified
6.1EPSS 0.009
CVE-2019-5314
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.
Published 2019-09-13 · Modified
6.1EPSS 0.006
CVE-2022-37896
A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.
Published 2022-10-07 · Modified
6.1EPSS 0.006
← Prev5 / 6Next →