Vulnerabilities > Arubanetworks > Arubaos
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-05 | CVE-2023-35975 | Path Traversal vulnerability in Arubanetworks Arubaos An authenticated path traversal vulnerability exists in the ArubaOS command line interface. | 8.1 |
2023-07-05 | CVE-2023-35976 | Unspecified vulnerability in Arubanetworks Arubaos Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. | 6.5 |
2023-07-05 | CVE-2023-35977 | Unspecified vulnerability in Arubanetworks Arubaos Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. | 6.5 |
2023-07-05 | CVE-2023-35978 | Cross-site Scripting vulnerability in Arubanetworks Arubaos A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface. | 6.1 |
2023-07-05 | CVE-2023-35979 | Classic Buffer Overflow vulnerability in Arubanetworks Arubaos There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. | 7.5 |
2023-05-08 | CVE-2023-22787 | An unauthenticated Denial of Service (DoS) vulnerability exists in a service accessed via the PAPI protocol provided by Aruba InstantOS and ArubaOS 10. | 7.5 |
2023-05-08 | CVE-2023-22788 | Command Injection vulnerability in multiple products Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. | 8.8 |
2023-05-08 | CVE-2023-22789 | Command Injection vulnerability in multiple products Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. | 8.8 |
2023-05-08 | CVE-2023-22790 | Command Injection vulnerability in multiple products Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. | 8.8 |
2023-05-08 | CVE-2023-22791 | A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. | 4.8 |