VendorsHPinstantosany version
Vulnerabilities

HP InstantOS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2023-45614
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2023-11-14 · Modified
9.8EPSS 0.021
CVE-2023-45616
There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2023-11-14 · Modified
9.8EPSS 0.021
CVE-2023-45615
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2023-11-14 · Modified
9.8EPSS 0.021
CVE-2023-22779
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-05-08 · Modified
9.8EPSS 0.021
CVE-2023-22786
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-05-08 · Modified
9.8EPSS 0.021
CVE-2023-22782
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-05-08 · Modified
9.8EPSS 0.021
CVE-2023-22780
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-05-08 · Modified
9.8EPSS 0.021
CVE-2023-35982
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-07-25 · Modified
9.8EPSS 0.021
CVE-2023-22783
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-05-08 · Modified
9.8EPSS 0.021
CVE-2023-22785
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-05-08 · Modified
9.8EPSS 0.021
CVE-2023-22781
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-05-08 · Modified
9.8EPSS 0.021
CVE-2023-22784
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-05-08 · Modified
9.8EPSS 0.021
CVE-2023-35980
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-07-25 · Modified
9.8EPSS 0.021
CVE-2023-35981
Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol
Published 2023-07-25 · Modified
9.8EPSS 0.021
CVE-2024-31473
There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
9.8EPSS 0.017
CVE-2024-31471
There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
9.8EPSS 0.016
CVE-2024-31472
There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
9.8EPSS 0.016
CVE-2024-31470
There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
9.8EPSS 0.012
CVE-2024-31467
Unauthenticated Buffer Overflow Vulnerabilities in CLI Service Accessed by the PAPI Protocol
Published 2024-05-14 · Modified
9.8EPSS 0.011
CVE-2024-31468
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
9.8EPSS 0.011
CVE-2024-31469
There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
9.8EPSS 0.011
CVE-2024-31466
Unauthenticated Buffer Overflow Vulnerabilities in CLI Service Accessed by the PAPI Protocol
Published 2024-05-14 · Modified
9.8EPSS 0.011
CVE-2024-42393
Unauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the Soft AP Daemon Service Accessed by the PAPI Protocol
Published 2024-08-06 · Analyzed
9.8EPSS 0.006
CVE-2024-42394
Unauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the Soft AP Daemon Service Accessed by the PAPI Protocol
Published 2024-08-06 · Analyzed
9.8EPSS 0.006
CVE-2024-42395
Unauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the AP Certificate Management Service Accessed by the PAPI Protocol
Published 2024-08-06 · Analyzed
9.8EPSS 0.004
CVE-2023-22790
Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface
Published 2023-05-08 · Modified
8.8EPSS 0.016
CVE-2023-22788
Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface
Published 2023-05-08 · Modified
8.8EPSS 0.016
CVE-2023-22789
Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface
Published 2023-05-08 · Modified
8.8EPSS 0.016
CVE-2024-31477
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
8.8EPSS 0.015
CVE-2024-31476
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2024-05-14 · Modified
8.8EPSS 0.015
CVE-2023-45617
There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Published 2023-11-14 · Modified
8.2EPSS 0.007
CVE-2023-45618
There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Published 2023-11-14 · Modified
8.2EPSS 0.007
CVE-2023-45619
There is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Published 2023-11-14 · Modified
8.2EPSS 0.007
CVE-2024-31474
There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point
Published 2024-05-14 · Modified
8.2EPSS 0.004
CVE-2024-31475
There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point.
Published 2024-05-14 · Modified
8.2EPSS 0.004
CVE-2023-45620
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
CVE-2023-45621
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
CVE-2023-45622
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
CVE-2023-45623
Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
CVE-2023-45624
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.
Published 2023-11-14 · Modified
7.5EPSS 0.009
1 / 2Next →