Vulnerability index

Browse CVEs

523 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Arubaos CRITICAL 9.8
CVE-2018-7081EPSS 6%

A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmi…

Fix: 6.4.4.21 / 6.5.4.13+
Fix from $2,300 2019-09-13
Aruba Instant CRITICAL 9.8
CVE-2018-7084

A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary…

Fix: 4.2.4.12 / 6.5.4.11+
Fix from $2,300 2019-05-10
Aruba Instant MEDIUM 6.1
CVE-2018-7064

A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnera…

Fix: 4.2.4.12 / 6.5.4.11+
Fix from $1,600 2019-05-10
Aruba Instant HIGH 7.5
CVE-2018-7083

If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time i…

Fix: 4.2.4.12 / 6.5.4.11+
Fix from $1,950 2019-05-10
Aruba Instant HIGH 7.2
CVE-2018-7082

A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the …

Fix: 4.2.4.12 / 6.5.4.11+
Fix from $1,950 2019-05-10
Clearpass Policy Manager CRITICAL 9.0
CVE-2018-7066

An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices. The ClearPass OnConnect feature permits admin…

Fix: 6.6.10 / 6.7.5+
Fix from $2,300 2018-12-07
Clearpass Policy Manager HIGH 8.1
CVE-2018-7063

In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been di…

Fix: 6.6.10 / 6.7.3+
Fix from $1,950 2018-12-07
Arubaos HIGH 7.5
CVE-2018-7080

A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulne…

Fix: 6.4.4.20 / 6.5.3.9+
Fix from $1,950 2018-12-07
Clearpass Policy Manager HIGH 7.2
CVE-2018-7065

An authenticated SQL injection vulnerability in Aruba ClearPass Policy Manager can lead to privilege escalation. All versions of ClearPass are affect…

Fix: 6.6.10 / 6.7.6+
Fix from $1,950 2018-12-07
Clearpass Policy Manager HIGH 7.2
CVE-2018-7067

A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of Clea…

Fix: 6.6.10 / 6.7.6+
Fix from $1,950 2018-12-07
Clearpass Policy Manager HIGH 7.2
CVE-2018-7079

Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorizatio…

Fix: 6.6.10 / 6.7.6+
Fix from $1,950 2018-12-07
Clearpass HIGH 8.8
CVE-2018-7060

Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate…

Fix: 6.6.9 / 6.7.1+
Fix from $1,950 2018-08-06
Web Management Portal CRITICAL 9.8
CVE-2014-2592

Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an e…

Mitigation only
Fix from $2,300 2018-03-09
Clearpass HIGH 7.1
CVE-2014-2071

Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunnele…

Fix: 6.2.5.61640 / 6.3.0.61712+
Fix from $1,950 2018-01-08
Clearpass Policy Manager CRITICAL 9.8
CVE-2015-4650EPSS 6%

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code w…

Fix: after 6.4.6
Fix from $2,300 2017-10-16
Clearpass HIGH 8.8
CVE-2015-3655

Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attacker…

Fix: 6.4.7 / 6.5.2+
Fix from $1,950 2017-08-29
Clearpass HIGH 7.2
CVE-2015-3653

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files wi…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Clearpass HIGH 7.2
CVE-2015-3654

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via un…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Clearpass HIGH 7.2
CVE-2015-3656

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Clearpass HIGH 7.2
CVE-2015-3657

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Adm…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Clearpass HIGH 7.2
CVE-2015-4649

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via un…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Clearpass CRITICAL 9.8
CVE-2016-2034

SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.

Mitigation only
Fix from $2,300 2017-06-08
Clearpass Policy Manager HIGH 9.0
CVE-2015-1550

Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary fi…

Fix: after 6.4.4
Fix from $1,950 2015-05-28
Clearpass Policy Manager MEDIUM 6.5
CVE-2015-1392

Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to execute arbitrar…

Fix: after 6.4.4
Fix from $1,600 2015-05-28
Clearpass Policy Manager HIGH 9.0
CVE-2014-6628

Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via unspecified vectors.

Fix: after 6.4.5
Fix from $1,950 2015-05-28
Arubaos HIGH 7.2
CVE-2015-1388

The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point…

Fix: after 6.2.3.9
Fix from $1,950 2015-03-24
Instant Access Point Firmware HIGH 7.8
CVE-2015-1348

Heap-based buffer overflow in Aruba Instant (IAP) with firmware before 4.0.0.7 and 4.1.x before 4.1.1.2 allows remote attackers to cause a denial of …

Fix: after 4.0.0.6
Fix from $1,950 2015-02-03
Airwave HIGH 9.0
CVE-2014-8368

The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbit…

Fix: 7.7.14 / 8.0.5+
Fix from $1,950 2014-11-25
Clearpass Policy Manager HIGH 7.5
CVE-2014-8367

SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attacke…

Fix: 6.3.6 / 6.4.2+
Fix from $1,950 2014-11-25
Clearpass HIGH 9.0
CVE-2014-6627

Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a differe…

Fix: after 6.3.4
Fix from $1,950 2014-11-19