Vulnerabilities > Arubanetworks

DATE CVE VULNERABILITY TITLE RISK
2021-03-05 CVE-2021-26967 Cross-site Scripting vulnerability in Arubanetworks Airwave
A remote reflected cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks CWE-79
6.1
2021-03-05 CVE-2021-26966 SQL Injection vulnerability in Arubanetworks Airwave
A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks CWE-89
6.5
2021-03-05 CVE-2021-26965 SQL Injection vulnerability in Arubanetworks Airwave
A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks CWE-89
6.5
2021-03-05 CVE-2021-26964 Incorrect Authorization vulnerability in Arubanetworks Airwave
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks CWE-863
7.1
2021-03-05 CVE-2021-26963 Unspecified vulnerability in Arubanetworks Airwave
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks
7.2
2021-03-05 CVE-2021-26962 OS Command Injection vulnerability in Arubanetworks Airwave
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks CWE-78
7.2
2021-03-05 CVE-2021-26961 Cross-Site Request Forgery (CSRF) vulnerability in Arubanetworks Airwave
A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks CWE-352
8.8
2021-03-05 CVE-2021-26960 Cross-Site Request Forgery (CSRF) vulnerability in Arubanetworks Airwave
A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks CWE-352
8.8
2021-02-23 CVE-2021-26680 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2
2021-02-23 CVE-2021-26679 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2