Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Arubanetworks

First CVE: Nov 20, 2007Active for: 19 yearsTotal CVEs: 588
58.3
VTI Score
TOP TARGET

Arubanetworks' vulnerability footprint spans a broadly represented portfolio of wireless access points, network switching, policy management, and SD-WAN solutions that form critical infrastructure layers across enterprise campuses and branch deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the privileged network-control role these products occupy and the parsing complexity inherent to management interfaces and firmware handling. The recurring exposure centers on products such as ArubaOS, ClearPass Policy Manager, and SD-WAN appliances, and clusters persistently around command-injection, cross-site scripting, and SQL-injection weaknesses that arise in web management and configuration processing. Defenders should prioritize network-segment isolation for management interfaces, maintain inventory of ArubaOS and ClearPass deployments, and treat firmware updates for this vendor as security-critical rather than optional maintenance. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
587
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Arubanetworks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2007
18 years ago
Most Recent CVE
May 12, 2026
76 days ago

Products(214 total)

Top CVEs

Signals from CVEs in this vendor scope (587 CVEs).

587 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5638CRITICAL
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem
Mar 11, 20179.899YESYES
CVE-2017-14491CRITICAL
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Oct 4, 20179.885NOYES
CVE-2020-7115CRITICAL
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that
Jun 3, 20209.876NOYES
CVE-2021-25162HIGH
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and bel
Mar 30, 20218.150NOYES
CVE-2021-25156MEDIUM
A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; A
Mar 30, 20214.948NOYES
CVE-2021-25161MEDIUM
A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; A
Mar 30, 20216.146NOYES
CVE-2021-25158MEDIUM
A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.
Mar 30, 20215.945NOYES
CVE-2017-13099MEDIUM
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a
Dec 13, 20175.944NOYES
CVE-2022-23676CRITICAL
A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All vers
May 10, 20229.842NONO
CVE-2021-25155MEDIUM
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below;
Mar 30, 20216.537NOYES
View all 587 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products587 CVEs
33%
52%
14%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local19 (3.2%)
Network513 (87.4%)
Unknown33 (5.6%)
Physical5 (0.9%)
Adjacent Network17 (2.9%)
Attack Complexity
Low531 (90.5%)
High23 (3.9%)
Unknown33 (5.6%)
User Interaction
None492 (83.8%)
Unknown33 (5.6%)
Required62 (10.6%)
Privileges Required
Low152 (25.9%)
High210 (35.8%)
None192 (32.7%)
Unknown33 (5.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (587 CVEs).

CISA KEV
1 CVE
0.2% of CVEs· 99th percentile
Metasploit
2 CVEs
0.3% of CVEs· 97th percentile
Nuclei
2 CVEs
0.3% of CVEs· 95th percentile
ExploitDB
13 CVEs
2.2% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Arubanetworks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Arubanetworks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Arubanetworks's Products

View all 6 CNAs →

Top CWEs