Vulnerabilities > Arubanetworks > SD WAN

DATE CVE VULNERABILITY TITLE RISK
2023-03-01 CVE-2023-22777 Exposure of Resource to Wrong Sphere vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface.
network
low complexity
arubanetworks CWE-668
6.5
2023-03-01 CVE-2023-22778 Cross-site Scripting vulnerability in Arubanetworks Arubaos and Sd-Wan
A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
arubanetworks CWE-79
4.8
2022-12-12 CVE-2022-37897 OS Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211).
network
low complexity
arubanetworks CWE-78
critical
9.8
2022-12-12 CVE-2022-37898 OS Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-78
7.2
2022-12-12 CVE-2022-37899 OS Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-78
7.2
2022-12-12 CVE-2022-37900 OS Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-78
7.2
2022-12-12 CVE-2022-37901 OS Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-78
7.2
2022-12-12 CVE-2022-37902 OS Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-78
7.2
2022-12-12 CVE-2022-37903 Out-of-bounds Write vulnerability in Arubanetworks Arubaos and Sd-Wan
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface.
network
low complexity
arubanetworks CWE-787
8.8
2022-12-12 CVE-2022-37904 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence.
network
low complexity
arubanetworks
8.8