Hewlett Packard Enterprise (HPE) Vulnerabilities and Affected Products
Vulnerabilities associated with HPE Aruba Networking AOS.
Products
Clear product- Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central51 vulnerabilities
- ArubaOS (AOS)34 vulnerabilities
- Aruba ClearPass Policy Manager33 vulnerabilities
- EdgeConnect SD-WAN Orchestrator27 vulnerabilities
- HPE Aruba Networking Wireless Operating System (AOS)27 vulnerabilities
- Aruba EdgeConnect Enterprise Software23 vulnerabilities
- AOS-8 Instant and AOS-10 AP18 vulnerabilities
- Aruba Access Points running InstantOS and ArubaOS 1016 vulnerabilities
- Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series;14 vulnerabilities
- Aruba EdgeConnect Enterprise Orchestration Software13 vulnerabilities
- AOS-CX12 vulnerabilities
- HPE OneView11 vulnerabilities
- HPE Aruba Networking ClearPass Policy Manager10 vulnerabilities
- HPE Aruba Networking EdgeConnect SD-WAN Gateway9 vulnerabilities
- HPE Athonet Core8 vulnerabilities
- HPE StoreOnce Software8 vulnerabilities
- ArubaOS Wi-Fi Controllers and Campus/Remote Access Points7 vulnerabilities
- HPE 3PAR Service Processor7 vulnerabilities
- Aruba OS6 vulnerabilities
- HPE 3PAR StoreServ Management and Core Software Media6 vulnerabilities
- HPE Aruba Networking Access Points, Instant AOS-8, and AOS-106 vulnerabilities
- HPE Aruba Networking AOS6 vulnerabilities
- HPE Aruba Networking AOS-CX5 vulnerabilities
- HPE Aruba Networking EdgeConnect SD-WAN5 vulnerabilities
- HPE Aruba Networking Fabric Composer (AFC)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-27084MEDIUM | Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal (CP) of an AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-based Management InterfaceA vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface. CWE-79Apr 8, 2025 | CVSS5.4v3.1 | EPSS0.263% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27085MEDIUM | Arbitrary File Download Vulnerabilities in Web-Based Management Interface of AOS-10 GW and AOS-8 Controller/Mobility ConductorMultiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. CWE-22Apr 8, 2025 | CVSS4.9v3.1 | EPSS0.586% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27083HIGH | Authenticated Command Injection Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceAuthenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system. CWE-77Apr 8, 2025 | CVSS7.2v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27082HIGH | Authenticated Remote Code Execution Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File WriteArbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system. CWE-434Apr 8, 2025 | CVSS7.2v3.1 | EPSS0.513% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-23052HIGH | Authenticated Command Injection Vulnerability allows Unauthorized Command Execution in CLI InterfaceAuthenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. CWE-77Jan 14, 2025 | CVSS7.2v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-23051HIGH | Authenticated Remote Code Execution in AOS Web-based Management InterfaceAn authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files. CWE-94Jan 14, 2025 | CVSS7.2v3.1 | EPSS0.713% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |