CVE-2019-5314
- EPSS 0.3%
- Veröffentlicht 13.09.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:44:43
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.
- EPSS 1.56%
- Veröffentlicht 13.09.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:44:44
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install b...
CVE-2018-7081
- EPSS 1.94%
- Veröffentlicht 13.09.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:11:37
A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a ...
CVE-2018-7080
- EPSS 0.24%
- Veröffentlicht 07.12.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:11:37
A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gai...
CVE-2017-14491
- EPSS 49.79%
- Veröffentlicht 04.10.2017 01:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
CVE-2015-1388
- EPSS 0.63%
- Veröffentlicht 24.03.2015 17:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors.
CVE-2014-7299
- EPSS 0.19%
- Veröffentlicht 08.10.2014 01:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authentication, and obtain potentially sensitive information or add guest acco...
CVE-2013-2290
- EPSS 0.43%
- Veröffentlicht 28.03.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the dashboard of the ArubaOS Administration WebUI in Aruba Networks ArubaOS 6.2.x before 6.2.0.3, 6.1.3.x before 6.1.3.7, 6.1.x-FIPS before 6.1.4.3-FIPS, and 6.1.x-AirGroup before 6.1.3.6-AirGroup, as used ...
CVE-2009-3836
- EPSS 0.37%
- Veröffentlicht 02.11.2009 15:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
ArubaOS 3.3.1.x, 3.3.2.x, RN 3.1.x, 3.4.x, and 3.3.2.x-FIPS on the Aruba Mobility Controller allows remote attackers to cause a denial of service (Access Point crash) via a malformed 802.11 Association Request management frame.
CVE-2008-7095
- EPSS 0.3%
- Veröffentlicht 27.08.2009 18:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The SNMP daemon in ArubaOS 3.3.2.6 in Aruba Mobility Controller does not restrict SNMP access, which allows remote attackers to (1) read all SNMP community strings via SNMP-COMMUNITY-MIB::snmpCommunityName (1.3.6.1.6.3.18.1.1.1.2) or SNMP-VIEW-BASED-...