Vulnerabilities > Arubanetworks > Arubaos > 8.4.0.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-12 | CVE-2022-37908 | Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. | 6.5 |
2022-12-12 | CVE-2022-37909 | Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. high complexity arubanetworks | 5.3 |
2022-12-12 | CVE-2022-37910 | Classic Buffer Overflow vulnerability in Arubanetworks Arubaos and Sd-Wan A buffer overflow vulnerability exists in the ArubaOS command line interface. | 6.5 |
2022-12-12 | CVE-2022-37911 | XXE vulnerability in Arubanetworks Arubaos and Sd-Wan Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. | 5.5 |
2022-12-12 | CVE-2022-37912 | OS Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. | 8.8 |
2021-09-07 | CVE-2019-5318 | Cross-Site Request Forgery (CSRF) vulnerability in multiple products A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x: all versions prior to 8.8.0.0. | 6.5 |
2020-12-11 | CVE-2020-24637 | Unspecified vulnerability in Arubanetworks Arubaos Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. | 7.2 |
2020-12-11 | CVE-2020-24634 | Command Injection vulnerability in Arubanetworks Arubaos An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below. | 9.8 |
2020-12-11 | CVE-2020-24633 | Classic Buffer Overflow vulnerability in Arubanetworks Arubaos There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below. | 9.8 |
2019-09-13 | CVE-2018-7081 | Improper Input Validation vulnerability in Arubanetworks Arubaos A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. | 9.8 |