VendorsAruba Networksarubaosany version
Vulnerabilities

Aruba Networks ArubaOS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

228CVEs
CVE-2022-37892
A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address this security vulnerability.
Published 2022-10-07 · Modified
5.4EPSS 0.006
CVE-2023-22791
Aruba InstantOS and ArubaOS 10 Sensitive Information Disclosure
Published 2023-05-08 · Modified
5.4EPSS 0.002
CVE-2026-44873
Insufficient Session Invalidation on User Account Deactivation in AOS-8 Operating System
Published 2026-05-12 · Analyzed
5.4EPSS 0.002
CVE-2026-23601
Frame Injection via Shared GTK Allows Traffic Spoofing and Client Compromise
Published 2026-03-04 · Analyzed
5.4EPSS 0.001
CVE-2024-33518
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
Published 2024-05-01 · Analyzed
5.3EPSS 0.005
CVE-2024-25615
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
Published 2024-03-05 · Analyzed
5.3EPSS 0.005
CVE-2024-42398
Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI Protocol
Published 2024-08-06 · Modified
5.3EPSS 0.004
CVE-2024-42399
Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI Protocol
Published 2024-08-06 · Modified
5.3EPSS 0.004
CVE-2024-42400
Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI Protocol
Published 2024-08-06 · Analyzed
5.3EPSS 0.004
CVE-2025-37179
Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating System
Published 2026-01-13 · Analyzed
5.3EPSS 0.004
CVE-2022-37909
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.
Published 2022-11-03 · Modified
5.3EPSS 0.003
CVE-2026-23822
Unauthenticated XML External Entity Injection in AOS-8 Instant allows Denial of Service
Published 2026-05-12 · Analyzed
5.3EPSS 0.003
CVE-2021-37733
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.11, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.
Published 2021-09-07 · Modified
4.9EPSS 0.012
CVE-2022-37895
An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected AP of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.
Published 2022-10-07 · Modified
4.9EPSS 0.008
CVE-2023-22776
Authenticated Remote Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Read
Published 2023-02-28 · Modified
4.9EPSS 0.007
CVE-2025-27085
Arbitrary File Download Vulnerabilities in Web-Based Management Interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor
Published 2025-04-08 · Analyzed
4.9EPSS 0.006
CVE-2026-44874
Authenticated Arbitrary File Download via AOS-10 Web-Based Management Interface
Published 2026-05-12 · Analyzed
4.9EPSS 0.005
CVE-2025-37144
Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Published 2025-10-14 · Analyzed
4.9EPSS 0.004
CVE-2025-37145
Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Published 2025-10-14 · Analyzed
4.9EPSS 0.004
CVE-2025-37143
Authenticated Arbitrary File Download Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web Interface (Physical Access Required)
Published 2025-10-14 · Analyzed
4.9EPSS 0.004
CVE-2025-37141
Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Published 2025-10-14 · Analyzed
4.9EPSS 0.004
CVE-2025-37142
Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Published 2025-10-14 · Analyzed
4.9EPSS 0.004
CVE-2025-37140
Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Published 2025-10-14 · Analyzed
4.9EPSS 0.004
CVE-2023-22778
Authenticated Stored Cross-Site Scripting
Published 2023-02-28 · Modified
4.8EPSS 0.005
CVE-2026-23810
Cross-BSSID GTK Re-encryption and Traffic Injection
Published 2026-03-04 · Analyzed
4.3EPSS 0.002
CVE-2026-23811
Unauthorized Bi-Directional Traffic Interception via L2/L3 Manipulation
Published 2026-03-04 · Analyzed
4.3EPSS 0.002
CVE-2026-23812
Security Boundary Bypass via Routing Node Impersonation
Published 2026-03-04 · Analyzed
4.3EPSS 0.001
CVE-2024-25616
Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.
Published 2024-03-05 · Analyzed
3.7EPSS 0.003
← Prev6 / 6