Vulnerabilities > Arubanetworks > Arubaos > 10.3.1.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-03-01 | CVE-2023-22775 | Exposure of Resource to Wrong Sphere vulnerability in Arubanetworks Arubaos and Sd-Wan A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface. | 6.5 |
2023-03-01 | CVE-2023-22776 | Path Traversal vulnerability in Arubanetworks Arubaos and Sd-Wan An authenticated path traversal vulnerability exists in the ArubaOS command line interface. | 4.9 |
2023-03-01 | CVE-2023-22777 | Exposure of Resource to Wrong Sphere vulnerability in Arubanetworks Arubaos and Sd-Wan An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. | 6.5 |
2023-03-01 | CVE-2023-22778 | Cross-site Scripting vulnerability in Arubanetworks Arubaos and Sd-Wan A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. | 4.8 |
2022-10-07 | CVE-2022-37893 | OS Command Injection vulnerability in multiple products An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. | 7.8 |
2022-10-07 | CVE-2022-37894 | An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. | 6.5 |
2022-10-07 | CVE-2022-37895 | An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10. | 4.9 |
2022-10-07 | CVE-2022-37896 | Cross-site Scripting vulnerability in multiple products A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. | 6.1 |
2022-10-07 | CVE-2022-37885 | Classic Buffer Overflow vulnerability in multiple products There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). | 9.8 |
2022-10-07 | CVE-2022-37886 | Classic Buffer Overflow vulnerability in multiple products There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). | 9.8 |