Aruba Networks has a focused vulnerability profile centered on its wireless mobility controller products, which serve as centralized management and access points for enterprise campus and branch networks. The recurring exposure reflects characteristic input-handling and authentication weaknesses in web-facing management interfaces, including cross-site scripting and improper authentication mechanisms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aruba Networks over time
Signals from CVEs in this vendor scope (587 CVEs).
587 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5638CRITICAL The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem | Mar 11, 2017 | 9.8 | 99 | YES | YES |
CVE-2017-14491CRITICAL Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | Oct 4, 2017 | 9.8 | 85 | NO | YES |
CVE-2020-7115CRITICAL The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that | Jun 3, 2020 | 9.8 | 76 | NO | YES |
CVE-2021-25162HIGH A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and bel | Mar 30, 2021 | 8.1 | 50 | NO | YES |
CVE-2021-25156MEDIUM A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; A | Mar 30, 2021 | 4.9 | 48 | NO | YES |
CVE-2021-25161MEDIUM A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; A | Mar 30, 2021 | 6.1 | 46 | NO | YES |
CVE-2021-25158MEDIUM A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8. | Mar 30, 2021 | 5.9 | 45 | NO | YES |
CVE-2017-13099MEDIUM wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a | Dec 13, 2017 | 5.9 | 44 | NO | YES |
CVE-2022-23676CRITICAL A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All vers | May 10, 2022 | 9.8 | 42 | NO | NO |
CVE-2021-25155MEDIUM A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; | Mar 30, 2021 | 6.5 | 37 | NO | YES |
Signals from CVEs in this vendor scope (587 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aruba Networks.
Media articles that mention a CVE ID that affects a product developed by Aruba Networks — matched by CVE ID, not by vendor name.