Vulnerabilities > Arubanetworks > Arubaos > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-12-12 CVE-2022-37909 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs.
high complexity
arubanetworks
5.3
2022-12-12 CVE-2022-37910 Classic Buffer Overflow vulnerability in Arubanetworks Arubaos and Sd-Wan
A buffer overflow vulnerability exists in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-120
6.5
2022-12-12 CVE-2022-37911 XXE vulnerability in Arubanetworks Arubaos and Sd-Wan
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS.
network
low complexity
arubanetworks CWE-611
5.5
2022-10-07 CVE-2022-37894 An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10.
low complexity
arubanetworks siemens
6.5
2022-10-07 CVE-2022-37895 An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba InstantOS and ArubaOS 10.
network
low complexity
arubanetworks siemens
4.9
2022-10-07 CVE-2022-37896 Cross-site Scripting vulnerability in multiple products
A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
arubanetworks siemens CWE-79
6.1
2022-10-07 CVE-2022-37892 Cross-site Scripting vulnerability in multiple products
A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
arubanetworks siemens CWE-79
5.4
2021-09-07 CVE-2019-5318 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x: all versions prior to 8.8.0.0.
network
low complexity
arubanetworks siemens CWE-352
6.5
2021-09-07 CVE-2021-37728 Path Traversal vulnerability in multiple products
A remote path traversal vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.8.0.1, 8.7.1.4, 8.6.0.11, 8.5.0.13.
network
low complexity
arubanetworks siemens CWE-22
6.5
2021-09-07 CVE-2021-37729 Path Traversal vulnerability in multiple products
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.3, 8.6.0.9, 8.5.0.12, 8.3.0.16, 6.5.4.19, 6.4.4.25.
network
low complexity
arubanetworks siemens CWE-22
6.5