Vulnerability index

Browse CVEs

523 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Arubaos HIGH 7.2
CVE-2025-27082

Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operat…

Fix: 8.10.0.16 / 8.12.0.4+
Fix from $1,950 2025-04-08
Arubaos HIGH 7.2
CVE-2025-27083

Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Succes…

Fix: 8.10.0.16 / 8.12.0.4+
Fix from $1,950 2025-04-08
Arubaos MEDIUM 6.1
CVE-2025-27084

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cr…

Fix: 8.10.0.16 / 8.12.0.4+
Fix from $1,600 2025-04-08
Clearpass Policy Manager HIGH 8.8
CVE-2025-25039

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to ru…

Fix: 6.11.10 / 6.12.4+
Fix from $1,950 2025-02-04
Clearpass Policy Manager HIGH 8.1
CVE-2025-23058

A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to g…

Fix: 6.11.10 / 6.12.4+
Fix from $1,950 2025-02-04
Clearpass Policy Manager HIGH 8.1
CVE-2025-23060

A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiti…

Fix: 6.11.10 / 6.12.4+
Fix from $1,950 2025-02-04
Fabric Composer MEDIUM 6.5
CVE-2025-23054

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator use…

Fix: 7.1.1+
Fix from $1,600 2025-01-28
Fabric Composer MEDIUM 5.4
CVE-2025-23055

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a sto…

Fix: 7.1.1+
Fix from $1,600 2025-01-28
Fabric Composer MEDIUM 5.4
CVE-2025-23056

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a sto…

Fix: 7.1.1+
Fix from $1,600 2025-01-28
Fabric Composer MEDIUM 5.4
CVE-2025-23057

A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a sto…

Fix: 7.1.1+
Fix from $1,600 2025-01-28
Fabric Composer MEDIUM 6.5
CVE-2025-23053

A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation co…

Fix: 7.1.1+
Fix from $1,600 2025-01-28
Clearpass Policy Manager HIGH 8.0
CVE-2024-51772

An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary …

Fix: 6.11.10 / 6.12.3+
Fix from $1,950 2024-12-03
Clearpass Policy Manager MEDIUM 6.3
CVE-2024-53672

A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the und…

Fix: 6.11.10 / 6.12.3+
Fix from $1,600 2024-12-03
Clearpass Policy Manager MEDIUM 5.4
CVE-2024-51773

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to c…

Fix: 6.11.10 / 6.12.3+
Fix from $1,600 2024-12-03
Clearpass Policy Manager HIGH 8.8
CVE-2024-51771

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor …

Fix: 6.11.10 / 6.12.3+
Fix from $1,950 2024-12-03
Arubaos MEDIUM 5.3
CVE-2024-42398

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation …

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $1,600 2024-08-06
Arubaos MEDIUM 5.3
CVE-2024-42399

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation …

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $1,600 2024-08-06
Arubaos MEDIUM 5.3
CVE-2024-42400

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation …

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $1,600 2024-08-06
Arubaos CRITICAL 9.8
CVE-2024-42395

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successf…

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $2,300 2024-08-06
Arubaos CRITICAL 9.8
CVE-2024-42393

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploit…

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $2,300 2024-08-06
Arubaos CRITICAL 9.8
CVE-2024-42394

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploit…

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $2,300 2024-08-06
Clearpass Policy Manager HIGH 8.8
CVE-2024-41915

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injecti…

Fix: 6.11.9 / 6.12.2+
Fix from $1,950 2024-07-30
Edgeconnect Sd Wan Orchestrator HIGH 8.8
CVE-2024-41136

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful ex…

Fix: after 9.2.9
Fix from $1,950 2024-07-24
Edgeconnect Sd Wan Orchestrator MEDIUM 6.1
CVE-2024-22444

A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cro…

Fix: 9.3.3 / 9.4.2+
Fix from $1,600 2024-07-24
Edgeconnect Sd Wan Orchestrator CRITICAL 9.0
CVE-2024-41914

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a st…

Fix: after 9.4.1
Fix from $2,300 2024-07-24
Edgeconnect Sd Wan Orchestrator HIGH 8.8
CVE-2024-22443

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a se…

Fix: 9.1.10 / 9.2.10+
Fix from $1,950 2024-07-24
Arubaos MEDIUM 6.5
CVE-2024-31483

An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of …

Fix: 8.6.0.24 / 8.10.0.11+
Fix from $1,600 2024-05-14
Arubaos HIGH 7.5
CVE-2024-31480

Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vul…

Fix: 8.6.0.24 / 8.10.0.11+
Fix from $1,950 2024-05-14
Arubaos HIGH 7.5
CVE-2024-31481

Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vul…

Fix: 8.6.0.24 / 8.10.0.11+
Fix from $1,950 2024-05-14
Arubaos HIGH 7.5
CVE-2024-31482

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitati…

Fix: 8.6.0.24 / 8.10.0.11+
Fix from $1,950 2024-05-14