arubanetworks

578 tracked vulnerabilities.

CVE-2022-37926 MEDIUM
Aruba EdgeConnect Enterprise < 8.3.7.1 - Stored Cross-Site Scripting via File Upload
Dec 12, 2022
CVSS 5.5
EPSS 0.00
CVE-2022-37925 MEDIUM
Aruba EdgeConnect Enterprise < 8.3.7.1 - Reflected Cross-Site Scripting via Web Management Interface
Dec 12, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-37924 HIGH
Aruba EdgeConnect Enterprise < 8.3.7.1 - Authenticated OS Command Injection via CLI
Dec 12, 2022
CVSS 7.2
EPSS 0.01
CVE-2022-37923 HIGH
Aruba EdgeConnect Enterprise <9.2.1.0 - Command Injection
Dec 12, 2022
CVSS 7.2
EPSS 0.01
CVE-2022-37922 HIGH
Aruba EdgeConnect Enterprise <9.2.1.0 - Command Injection
Dec 12, 2022
CVSS 7.2
EPSS 0.01
CVE-2022-37921 HIGH
Aruba EdgeConnect Enterprise <9.2.1.0 - Command Injection
Dec 12, 2022
CVSS 7.2
EPSS 0.01
CVE-2022-37920 HIGH
Aruba EdgeConnect Enterprise <9.2.1.0 - Command Injection
Dec 12, 2022
CVSS 7.2
EPSS 0.01
CVE-2022-37919 HIGH
Aruba EdgeConnect Enterprise <9.2.1.0 - DoS
Dec 12, 2022
CVSS 7.5
EPSS 0.01
CVE-2022-37912 HIGH
ArubaOS 6.5.4.0-6.5.4.21 and SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.5 - Authenticated OS Command Injection
Dec 12, 2022
CVSS 7.2
EPSS 0.02
CVE-2022-37911 LOW
ArubaOS 6.5.4.0-6.5.4.21 and SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.5 - Authenticated XML External Entity Injection
Dec 12, 2022
CVSS 3.8
EPSS 0.00
CVE-2022-37910 MEDIUM
ArubaOS 6.5.4.0-6.5.4.21 & SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.5 DoS via CLI Buffer Overflow
Dec 12, 2022
CVSS 4.4
EPSS 0.00
CVE-2022-37909 MEDIUM
Aruba SD-WAN 8.7.0.0-2.3.0.5 & ArubaOS 6.5.4.0-6.5.4.21 - Sensitive Information Exposure via ESSID
Dec 12, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-37908 MEDIUM
ArubaOS 6.5.4.0-6.5.4.21 and SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.5 - Authenticated Bootloader Integrity Compromise
Dec 12, 2022
CVSS 5.8
EPSS 0.00
CVE-2022-37907 MEDIUM
ArubaOS 6.5.4.0-6.5.4.21 and SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.5 - Denial of Service via Bootloader
Dec 12, 2022
CVSS 5.8
EPSS 0.00
CVE-2022-37906 MEDIUM
ArubaOS 6.5.4.0-6.5.4.21 and SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.5 - Authenticated Path Traversal
Dec 12, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-37905 MEDIUM
ArubaOS 7xxx Controllers - Boot Sequence Remote Code Execution
Dec 12, 2022
CVSS 6.6
EPSS 0.02
CVE-2022-37904 MEDIUM
ArubaOS 7xxx Controllers - Boot Sequence Remote Code Execution
Dec 12, 2022
CVSS 6.6
EPSS 0.01
CVE-2022-37903 HIGH
Aruba SD-WAN 8.7.0.0-2.3.0.6 & ArubaOS 6.5.4.0-6.5.4.22 - Authenticated Arbitrary File Write
Dec 12, 2022
CVSS 7.2
EPSS 0.01
CVE-2022-37902 HIGH
ArubaOS SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.6 and ArubaOS 6.5.4.0-6.5.4.22 - Authenticated OS Command Injection
Dec 12, 2022
CVSS 7.2
EPSS 0.02
CVE-2022-37901 HIGH
ArubaOS 6.5.4.0-6.5.4.22 and SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.6 - Authenticated OS Command Injection
Dec 12, 2022
CVSS 7.2
EPSS 0.02
CVE-2022-37900 HIGH
ArubaOS 6.5.4.0-6.5.4.22 and SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.6 - Authenticated OS Command Injection
Dec 12, 2022
CVSS 7.2
EPSS 0.02
CVE-2022-37899 HIGH
ArubaOS SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.6 and ArubaOS 6.5.4.0-6.5.4.22 - Authenticated OS Command Injection
Dec 12, 2022
CVSS 7.2
EPSS 0.02
CVE-2022-37898 HIGH
ArubaOS and SD-WAN - Authenticated OS Command Injection via Command Line Interface
Dec 12, 2022
CVSS 7.2
EPSS 0.02
CVE-2022-37897 CRITICAL
Aruba SD-WAN 8.7.0.0-2.3.0.5 & ArubaOS 6.5.4.0-6.5.4.21 - RCE via PAPI UDP Port
Dec 12, 2022
CVSS 9.8
EPSS 0.01
CVE-2022-37918 HIGH
Aruba AirWave < 8.2.15.0 - Improper Access Control in Web Management Interface
Dec 08, 2022
CVSS 8.1
EPSS 0.00