CVE-2021-37728
- EPSS 0.69%
- Veröffentlicht 07.09.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:49
A remote path traversal vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.8.0.1, 8.7.1.4, 8.6.0.11, 8.5.0.13. Aruba has released patches for ArubaOS that address this security vulnerability.
- EPSS 0.24%
- Veröffentlicht 11.12.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:15:17
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobil...
- EPSS 0.52%
- Veröffentlicht 11.12.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:15:18
Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this vulnerability this could lead to remote compromise of system integrity by allowing an attacker to load an untrusted or mo...
- EPSS 1.34%
- Veröffentlicht 11.12.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 05:15:17
There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or control...
CVE-2016-2031
- EPSS 0.97%
- Veröffentlicht 31.01.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 02:47:39
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sens...
CVE-2016-2032
- EPSS 2.17%
- Veröffentlicht 31.01.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 02:47:39
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on T...
CVE-2019-5314
- EPSS 0.36%
- Veröffentlicht 13.09.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:44:43
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.
- EPSS 1.82%
- Veröffentlicht 13.09.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:44:44
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install b...
CVE-2018-7081
- EPSS 1.94%
- Veröffentlicht 13.09.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:11:37
A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a ...
CVE-2018-7080
- EPSS 0.24%
- Veröffentlicht 07.12.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:11:37
A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gai...