Vulnerabilities > Arubanetworks > High

DATE CVE VULNERABILITY TITLE RISK
2021-04-29 CVE-2021-29140 XXE vulnerability in Arubanetworks Clearpass
A remote XML external entity (XXE) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.9, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-611
8.2
2021-04-29 CVE-2021-29147 OS Command Injection vulnerability in Arubanetworks Clearpass
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
8.8
2021-04-29 CVE-2021-25167 OS Command Injection vulnerability in Arubanetworks Airwave
A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.
network
low complexity
arubanetworks CWE-78
8.8
2021-04-29 CVE-2021-25166 OS Command Injection vulnerability in Arubanetworks Airwave
A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.
network
low complexity
arubanetworks CWE-78
8.8
2021-04-29 CVE-2021-25163 XXE vulnerability in Arubanetworks Airwave
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.
network
low complexity
arubanetworks CWE-611
8.1
2021-04-28 CVE-2021-25165 XXE vulnerability in Arubanetworks Airwave
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.
network
low complexity
arubanetworks CWE-611
8.1
2021-04-28 CVE-2021-25152 Deserialization of Untrusted Data vulnerability in Arubanetworks Airwave
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.
network
low complexity
arubanetworks CWE-502
7.2
2021-04-28 CVE-2021-25154 Unspecified vulnerability in Arubanetworks Airwave
A remote escalation of privilege vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.
network
high complexity
arubanetworks
7.5
2021-04-28 CVE-2021-25153 SQL Injection vulnerability in Arubanetworks Airwave
A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.
network
low complexity
arubanetworks CWE-89
8.1
2021-04-28 CVE-2021-25151 Deserialization of Untrusted Data vulnerability in Arubanetworks Airwave
A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.
network
low complexity
arubanetworks CWE-502
8.8