Vulnerabilities > Arubanetworks

DATE CVE VULNERABILITY TITLE RISK
2020-02-27 CVE-2019-5326 Deserialization of Untrusted Data vulnerability in Arubanetworks Airwave
An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform.
network
low complexity
arubanetworks CWE-502
7.2
2020-02-27 CVE-2019-5323 Command Injection vulnerability in Arubanetworks Airwave
There are command injection vulnerabilities present in the AirWave application.
network
low complexity
arubanetworks CWE-77
7.2
2020-02-13 CVE-2019-5322 Unspecified vulnerability in Arubanetworks products
A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540.
network
low complexity
arubanetworks
7.5
2020-01-31 CVE-2016-2032 Improper Authentication vulnerability in Arubanetworks Aruba Instant and Arubaos
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information.
network
low complexity
arubanetworks CWE-287
7.5
2020-01-31 CVE-2016-2031 Improper Input Validation vulnerability in multiple products
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary code.
network
low complexity
arubanetworks siemens CWE-20
critical
9.8
2019-11-06 CVE-2016-4401 Insufficiently Protected Credentials vulnerability in Arubanetworks Clearpass
Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
network
low complexity
arubanetworks CWE-522
critical
9.8
2019-10-30 CVE-2018-16417 Command Injection vulnerability in multiple products
Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.
network
low complexity
arubanetworks siemens CWE-77
7.5
2019-09-13 CVE-2019-5315 OS Command Injection vulnerability in Arubanetworks Arubaos
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system.
network
low complexity
arubanetworks CWE-78
7.2
2019-09-13 CVE-2019-5314 Injection vulnerability in Arubanetworks Arubaos
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS.
network
low complexity
arubanetworks CWE-74
6.1
2019-09-13 CVE-2018-7081 Improper Input Validation vulnerability in Arubanetworks Arubaos
A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS.
network
low complexity
arubanetworks CWE-20
critical
9.8