Vulnerabilities > Arubanetworks

DATE CVE VULNERABILITY TITLE RISK
2015-05-28 CVE-2014-6628 Remote Code Execution vulnerability in Aruba Networks ClearPass Policy Manager
Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via unspecified vectors.
network
low complexity
arubanetworks
critical
9.0
2015-03-24 CVE-2015-1388 OS Command Injection vulnerability in Arubanetworks Arubaos
The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors.
local
low complexity
arubanetworks CWE-78
7.2
2015-02-03 CVE-2015-1348 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arubanetworks Instant Access Point Firmware
Heap-based buffer overflow in Aruba Instant (IAP) with firmware before 4.0.0.7 and 4.1.x before 4.1.1.2 allows remote attackers to cause a denial of service (crash or reset to factory default) via a malformed frame to the wireless interface.
network
low complexity
arubanetworks CWE-119
7.8
2014-11-25 CVE-2014-8368 Permissions, Privileges, and Access Controls vulnerability in Arubanetworks Airwave
The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors.
network
low complexity
arubanetworks CWE-264
critical
9.0
2014-11-25 CVE-2014-8367 SQL Injection vulnerability in Arubanetworks Clearpass Policy Manager
SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
arubanetworks CWE-89
7.5
2014-11-19 CVE-2014-6627 Improper Access Control vulnerability in Arubanetworks Clearpass
Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-5342.
network
low complexity
arubanetworks CWE-284
critical
9.0
2014-11-19 CVE-2014-6626 Improper Access Control vulnerability in Arubanetworks Clearpass
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown vectors.
network
low complexity
arubanetworks CWE-284
critical
10.0
2014-11-19 CVE-2014-6625 Improper Access Control vulnerability in Arubanetworks Clearpass
The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecified vectors.
network
low complexity
arubanetworks CWE-284
critical
9.0
2014-11-19 CVE-2014-6624 Information Exposure vulnerability in Arubanetworks Clearpass
The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unspecified vectors.
network
low complexity
arubanetworks CWE-200
6.8
2014-11-19 CVE-2014-6622 Information Exposure vulnerability in Arubanetworks Clearpass
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors.
network
low complexity
arubanetworks CWE-200
5.0