Vulnerabilities > Arubanetworks > Arubaos > 8.6.0.11

DATE CVE VULNERABILITY TITLE RISK
2022-12-12 CVE-2022-37903 Out-of-bounds Write vulnerability in Arubanetworks Arubaos and Sd-Wan
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface.
network
low complexity
arubanetworks CWE-787
8.8
2022-12-12 CVE-2022-37904 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence.
network
low complexity
arubanetworks
8.8
2022-12-12 CVE-2022-37905 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence.
network
low complexity
arubanetworks
8.8
2022-12-12 CVE-2022-37906 Path Traversal vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated path traversal vulnerability exists in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-22
8.1
2022-12-12 CVE-2022-37907 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system.
network
low complexity
arubanetworks
7.5
2022-12-12 CVE-2022-37908 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers.
network
low complexity
arubanetworks
6.5
2022-12-12 CVE-2022-37909 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs.
high complexity
arubanetworks
5.3
2022-12-12 CVE-2022-37910 Classic Buffer Overflow vulnerability in Arubanetworks Arubaos and Sd-Wan
A buffer overflow vulnerability exists in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-120
6.5
2022-12-12 CVE-2022-37911 XXE vulnerability in Arubanetworks Arubaos and Sd-Wan
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS.
network
low complexity
arubanetworks CWE-611
5.5
2022-12-12 CVE-2022-37912 OS Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-78
8.8