Vulnerabilities > Arubanetworks > Arubaos > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-07-05 CVE-2023-35978 Cross-site Scripting vulnerability in Arubanetworks Arubaos
A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface.
network
low complexity
arubanetworks CWE-79
6.1
2023-05-08 CVE-2023-22791 A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN.
high complexity
arubanetworks hp
4.8
2023-03-01 CVE-2023-22772 Path Traversal vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface.
network
low complexity
arubanetworks CWE-22
6.5
2023-03-01 CVE-2023-22773 Path Traversal vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-22
6.5
2023-03-01 CVE-2023-22774 Path Traversal vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-22
6.5
2023-03-01 CVE-2023-22775 Exposure of Resource to Wrong Sphere vulnerability in Arubanetworks Arubaos and Sd-Wan
A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-668
6.5
2023-03-01 CVE-2023-22776 Path Traversal vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated path traversal vulnerability exists in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-22
4.9
2023-03-01 CVE-2023-22777 Exposure of Resource to Wrong Sphere vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface.
network
low complexity
arubanetworks CWE-668
6.5
2023-03-01 CVE-2023-22778 Cross-site Scripting vulnerability in Arubanetworks Arubaos and Sd-Wan
A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
arubanetworks CWE-79
4.8
2022-12-12 CVE-2022-37908 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers.
network
low complexity
arubanetworks
6.5