Vulnerabilities > Arubanetworks > Aruba Instant > 6.5.4.1

DATE CVE VULNERABILITY TITLE RISK
2021-10-12 CVE-2021-37732 OS Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x.x: 6.5.4.18 and below; Aruba Instant 8.5.x.x: 8.5.0.11 and below; Aruba Instant 8.6.x.x: 8.6.0.6 and below; Aruba Instant 8.7.x.x: 8.7.1.0 and below.
network
low complexity
arubanetworks siemens CWE-78
critical
9.0
2021-10-12 CVE-2021-37734 Path Traversal vulnerability in multiple products
A remote unauthorized read access to files vulnerability was discovered in Aruba Instant version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.19 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba Instant 8.7.x.x: 8.7.1.3 and below; Aruba Instant 8.8.x.x: 8.8.0.0 and below.
network
low complexity
arubanetworks siemens CWE-22
4.0
2021-10-12 CVE-2021-37735 Use of Externally-Controlled Format String vulnerability in multiple products
A remote denial of service vulnerability was discovered in Aruba Instant version(s): Aruba Instant 6.5.x.x: 6.5.4.18 and below; Aruba Instant 8.5.x.x: 8.5.0.10 and below; Aruba Instant 8.6.x.x: 8.6.0.4 and below.
network
low complexity
arubanetworks siemens CWE-134
5.0
2021-10-12 CVE-2021-37727 OS Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.20 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba Instant 8.7.x.x: 8.7.1.3 and below.
network
low complexity
arubanetworks siemens CWE-78
critical
9.0
2021-10-12 CVE-2021-37730 OS Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.20 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba Instant 8.7.x.x: 8.7.1.3 and below.
network
low complexity
arubanetworks siemens CWE-78
critical
9.0
2019-05-10 CVE-2018-7084 OS Command Injection vulnerability in multiple products
A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system.
network
low complexity
arubanetworks siemens CWE-78
critical
9.8
2019-05-10 CVE-2018-7064 Cross-site Scripting vulnerability in multiple products
A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface.
4.3
2019-05-10 CVE-2018-7083 Information Exposure vulnerability in multiple products
If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it crashed.
network
low complexity
arubanetworks siemens CWE-200
5.0
2019-05-10 CVE-2018-7082 OS Command Injection vulnerability in multiple products
A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system.
network
low complexity
arubanetworks siemens CWE-78
7.2