Aruba's vulnerability profile centers on a narrow product line of wireless and mobility infrastructure, including controllers, instant-access points, and caching appliances that serve enterprise network deployments. The observed exposure recurs through information-disclosure weaknesses and web-application input-handling issues such as cross-site scripting, reflecting the administrative interfaces and web-management surfaces typical of network appliances. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aruba over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44983HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aruba.It Aruba HiSpeed Cache.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.6. | Dec 19, 2023 | 7.5 | 21 | NO | NO |
CVE-2021-34618MEDIUM A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Arub | Jul 19, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-34617MEDIUM A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.13 and below; A | Jul 19, 2021 | 6.1 | 21 | NO | NO |
CVE-2007-0931HIGH Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows r | Feb 14, 2007 | 7.5 | 21 | NO | NO |
CVE-2007-0932HIGH The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignme | Feb 14, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-4023MEDIUM Cross-site scripting (XSS) vulnerability in the login CGI program in Aruba Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier FIPS versions, allows remote attac | Jul 26, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aruba.
Media articles that mention a CVE ID that affects a product developed by Aruba — matched by CVE ID, not by vendor name.