📦 Arubaos

by Arubanetworks

🔍 What is Arubaos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-42394

CRITICAL CVSS 9.8 Aug 6, 2024

This vulnerability in the Soft AP Daemon Service allows unauthenticated remote attackers to execute arbitrary commands on affected systems, leading to complete system compromise. It affects HPE Aruba ...

CVE-2024-31473

CRITICAL CVSS 9.8 May 14, 2024

This critical vulnerability in Aruba access points allows unauthenticated attackers to execute arbitrary commands with root privileges by sending malicious packets to port 8211. It affects ArubaOS 10 ...

CVE-2024-31469

CRITICAL CVSS 9.8 May 14, 2024

CVE-2024-31469 is a critical buffer overflow vulnerability in Aruba's Central Communications service that allows unauthenticated attackers to execute arbitrary code with privileged access by sending m...

CVE-2024-31471

CRITICAL CVSS 9.8 May 14, 2024

CVE-2024-31471 is a critical command injection vulnerability in Aruba's Central Communications service that allows unauthenticated attackers to execute arbitrary code with privileged access by sending...

CVE-2024-31467

CRITICAL CVSS 9.8 May 14, 2024

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2024-31466

CRITICAL CVSS 9.8 May 14, 2024

CVE-2024-31466 is a critical buffer overflow vulnerability in Aruba's Access Point management protocol (PAPI) that allows unauthenticated attackers to execute arbitrary code with privileged access by ...

CVE-2023-45614

CRITICAL CVSS 9.8 Nov 14, 2023

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2023-45616

CRITICAL CVSS 9.8 Nov 14, 2023

This CVE describes a critical buffer overflow vulnerability in Aruba's AirWave client service that allows unauthenticated attackers to execute arbitrary code with privileged access by sending speciall...

CVE-2023-35980

CRITICAL CVSS 9.8 Jul 25, 2023

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2023-35982

CRITICAL CVSS 9.8 Jul 25, 2023

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2023-22747

CRITICAL CVSS 9.8 Mar 1, 2023

CVE-2023-22747 allows unauthenticated attackers to execute arbitrary commands on Aruba access points by sending malicious packets to UDP port 8211. This enables remote code execution with privileged s...

CVE-2023-22749

CRITICAL CVSS 9.8 Mar 1, 2023

CVE-2023-22749 allows unauthenticated attackers to execute arbitrary commands on Aruba access points by sending malicious packets to the PAPI UDP port 8211. This affects ArubaOS and Aruba InstantOS ac...

CVE-2023-22751

CRITICAL CVSS 9.8 Mar 1, 2023

CVE-2023-22751 is a critical stack-based buffer overflow vulnerability in Aruba Networks' PAPI protocol that allows unauthenticated attackers to execute arbitrary code with privileged access on affect...

CVE-2021-37716

CRITICAL CVSS 9.8 Sep 7, 2021

A remote buffer overflow vulnerability in Aruba SD-WAN Software and Gateways allows attackers to execute arbitrary code or cause denial of service. Affected systems include ArubaOS versions prior to s...

CVE-2020-24634

CRITICAL CVSS 9.8 Dec 11, 2020

CVE-2020-24634 is a critical command injection vulnerability in Aruba networking devices that allows remote attackers to execute arbitrary commands by sending specially crafted packets to the PAPI UDP...

CVE-2025-37171

HIGH CVSS 7.2 Jan 13, 2026

Authenticated command injection vulnerabilities in Aruba mobility conductors running AOS-8 allow attackers with valid credentials to execute arbitrary commands with privileged system access. This affe...

CVE-2025-37172

HIGH CVSS 7.2 Jan 13, 2026

Authenticated command injection vulnerabilities in Aruba mobility conductors running AOS-8 allow authenticated attackers to execute arbitrary commands with privileged user permissions. This affects or...

CVE-2025-37173

HIGH CVSS 7.2 Jan 13, 2026

An authenticated attacker with valid credentials can exploit improper input handling in the web management interface of Aruba mobility conductors running AOS-10 or AOS-8 to trigger unintended system b...

CVE-2025-37174

HIGH CVSS 7.2 Jan 13, 2026

This vulnerability allows authenticated attackers to write arbitrary files on mobility conductors running AOS-10 or AOS-8, potentially leading to remote code execution as a privileged user. It affects...

CVE-2025-37175

HIGH CVSS 7.2 Jan 13, 2026

This vulnerability allows authenticated attackers to upload arbitrary files to mobility conductors running AOS-10 or AOS-8 operating systems. Successful exploitation could lead to remote code executio...

CVE-2025-37168

HIGH CVSS 8.2 Jan 13, 2026

An arbitrary file deletion vulnerability in Aruba mobility conductors running AOS-8 allows unauthenticated remote attackers to delete files on affected systems. This could lead to denial-of-service co...

CVE-2025-37169

HIGH CVSS 7.2 Jan 13, 2026

A stack overflow vulnerability in the AOS-10 web management interface of HPE Mobility Gateway allows authenticated attackers to execute arbitrary code with privileged system access. This affects organ...

CVE-2025-37170

HIGH CVSS 7.2 Jan 13, 2026

Authenticated command injection vulnerabilities in Aruba mobility conductors running AOS-8 allow attackers with valid credentials to execute arbitrary commands as privileged users on the underlying op...

CVE-2025-37161

HIGH CVSS 7.5 Nov 18, 2025

An unauthenticated remote denial-of-service vulnerability in HPE web management interfaces allows attackers to crash affected systems, requiring manual intervention to restore service. This affects HP...

CVE-2025-37134

HIGH CVSS 7.2 Oct 14, 2025

An authenticated command injection vulnerability in the CLI binary of AOS-8 Controller/Mobility Conductor allows attackers with valid credentials to execute arbitrary commands with privileged system a...

CVE-2025-37132

HIGH CVSS 7.2 Oct 14, 2025

An authenticated attacker can upload arbitrary files to the web management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor systems, potentially leading to remote command execution. This...

CVE-2025-37133

HIGH CVSS 7.2 Oct 14, 2025

An authenticated command injection vulnerability in the CLI binary of AOS-8 Controller/Mobility Conductor allows authenticated attackers to execute arbitrary commands as privileged users on the underl...

CVE-2024-31477

HIGH CVSS 7.2 May 14, 2024

This CVE describes authenticated command injection vulnerabilities in HPE Aruba Networking products that allow attackers with CLI access to execute arbitrary commands as privileged users on the underl...

CVE-2024-31475

HIGH CVSS 8.2 May 14, 2024

This vulnerability allows attackers to delete arbitrary files on Aruba Access Points through the Central Communications service via PAPI. Successful exploitation can disrupt operations and compromise ...

CVE-2024-25612

HIGH CVSS 7.2 Mar 5, 2024

Authenticated command injection vulnerabilities in ArubaOS CLI allow attackers with valid credentials to execute arbitrary commands as privileged users on the underlying operating system. This affects...

CVE-2024-1356

HIGH CVSS 7.2 Mar 5, 2024

Authenticated command injection vulnerabilities in ArubaOS CLI allow attackers with valid credentials to execute arbitrary commands as privileged users on the underlying operating system. This affects...

CVE-2023-45624

HIGH CVSS 7.5 Nov 14, 2023

An unauthenticated Denial-of-Service vulnerability in the soft AP daemon accessed via PAPI protocol allows attackers to disrupt affected access points without authentication. This affects Aruba access...

CVE-2023-45620

HIGH CVSS 7.5 Nov 14, 2023

Unauthenticated attackers can cause denial-of-service conditions in Aruba access points by exploiting vulnerabilities in the CLI service accessed via PAPI protocol. This affects Aruba access points wi...

CVE-2023-45622

HIGH CVSS 7.5 Nov 14, 2023

Unauthenticated attackers can exploit vulnerabilities in the BLE daemon service via the PAPI protocol to cause Denial-of-Service (DoS) on affected Aruba access points. This disrupts normal wireless ne...

CVE-2023-45618

HIGH CVSS 8.2 Nov 14, 2023

This vulnerability in Aruba's AirWave client service allows attackers to delete arbitrary files on the operating system via the PAPI protocol. This could disrupt normal operations and compromise syste...

CVE-2023-38484

HIGH CVSS 8.0 Sep 6, 2023

This vulnerability allows attackers to execute arbitrary code during the early boot sequence of Aruba 9200 and 9000 Series Controllers and Gateways. Successful exploitation could lead to complete syst...

CVE-2023-38486

HIGH CVSS 7.7 Sep 6, 2023

This vulnerability allows attackers to bypass secure boot protections on Aruba 9200 and 9000 Series Controllers and Gateways, enabling execution of arbitrary unsigned kernel images. Affected organizat...

CVE-2023-35971

HIGH CVSS 8.8 Jul 5, 2023

This stored cross-site scripting vulnerability in ArubaOS web management interface allows unauthenticated attackers to inject malicious scripts that execute in victims' browsers. Anyone using the vuln...

CVE-2023-35973

HIGH CVSS 7.2 Jul 5, 2023

Authenticated command injection vulnerabilities in ArubaOS CLI allow attackers with valid credentials to execute arbitrary commands as privileged users on the underlying OS. This affects Aruba network...

CVE-2023-22787

HIGH CVSS 7.5 May 8, 2023

An unauthenticated Denial of Service vulnerability in Aruba's PAPI protocol allows attackers to disrupt affected access points without credentials. This affects Aruba InstantOS and ArubaOS 10 systems,...

CVE-2023-22789

HIGH CVSS 7.2 May 8, 2023

This CVE describes authenticated command injection vulnerabilities in Aruba InstantOS and ArubaOS 10 command line interfaces. Attackers with authenticated access can execute arbitrary commands as priv...

CVE-2023-22773

HIGH CVSS 7.2 Mar 1, 2023

This CVE describes an authenticated path traversal vulnerability in ArubaOS command line interface that allows authenticated attackers to delete arbitrary files on the underlying operating system. It ...

CVE-2023-22757

HIGH CVSS 8.1 Mar 1, 2023

This CVE describes buffer overflow vulnerabilities in Aruba networking devices that allow unauthenticated attackers to execute arbitrary code with privileged permissions via specially crafted PAPI pro...

CVE-2023-22759

HIGH CVSS 7.2 Mar 1, 2023

CVE-2023-22759 is an authenticated remote command injection vulnerability in ArubaOS web management interfaces. It allows authenticated attackers to execute arbitrary commands as privileged users, lea...

CVE-2023-22761

HIGH CVSS 7.2 Mar 1, 2023

CVE-2023-22761 allows authenticated attackers to execute arbitrary commands as privileged users on ArubaOS devices through the web management interface. This results in complete compromise of the unde...

CVE-2023-22763

HIGH CVSS 7.2 Mar 1, 2023

This CVE describes authenticated command injection vulnerabilities in ArubaOS command line interface that allow attackers to execute arbitrary commands as privileged users on the underlying operating ...

CVE-2023-22765

HIGH CVSS 7.2 Mar 1, 2023

Authenticated command injection vulnerabilities in ArubaOS CLI allow attackers with valid credentials to execute arbitrary commands as privileged users on the underlying OS. This affects Aruba network...

CVE-2023-22767

HIGH CVSS 7.2 Mar 1, 2023

CVE-2023-22767 allows authenticated attackers to execute arbitrary commands with privileged access on ArubaOS devices through command injection in the CLI. This affects network administrators and orga...

CVE-2023-22769

HIGH CVSS 7.2 Mar 1, 2023

This CVE describes authenticated command injection vulnerabilities in ArubaOS command line interface. Attackers with valid credentials can execute arbitrary commands as privileged users on the underly...

CVE-2023-22753

HIGH CVSS 8.1 Mar 1, 2023

CVE-2023-22753 is a critical buffer overflow vulnerability in Aruba networking devices that allows unauthenticated attackers to execute arbitrary code with privileged system access via specially craft...

CVE-2023-22755

HIGH CVSS 8.1 Mar 1, 2023

This CVE describes buffer overflow vulnerabilities in Aruba networking devices that allow unauthenticated attackers to execute arbitrary code with privileged system access via specially crafted PAPI p...

CVE-2021-37718

HIGH CVSS 7.2 Sep 7, 2021

This CVE allows remote attackers to execute arbitrary commands on affected Aruba SD-WAN and gateway devices. The vulnerability stems from improper neutralization of special elements used in a command ...

CVE-2021-37720

HIGH CVSS 7.2 Sep 7, 2021

This CVE allows remote attackers to execute arbitrary commands on Aruba SD-WAN and gateway devices running vulnerable ArubaOS versions. Attackers can potentially take full control of affected systems ...

CVE-2021-37722

HIGH CVSS 7.2 Sep 7, 2021

This CVE allows remote attackers to execute arbitrary commands on Aruba SD-WAN and gateway devices through improper neutralization of special elements used in a command. Affected organizations include...

CVE-2021-37724

HIGH CVSS 7.2 Sep 7, 2021

This CVE allows remote attackers to execute arbitrary commands on ArubaOS network devices without authentication. It affects ArubaOS versions prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, and 8.3.0.16. Network...

CVE-2025-37179

MEDIUM CVSS 5.3 Jan 13, 2026

Multiple out-of-bounds read vulnerabilities in a system component that handles data buffers. Insufficient validation of buffer size values allows reading beyond intended memory regions, potentially ca...

CVE-2025-37176

MEDIUM CVSS 6.5 Jan 13, 2026

A command injection vulnerability in AOS-8 allows authenticated privileged users to inject shell commands by manipulating package headers. This could enable malicious actors to execute arbitrary comma...

CVE-2025-37177

MEDIUM CVSS 6.5 Jan 13, 2026

An arbitrary file deletion vulnerability in the command-line interface of Aruba mobility conductors running AOS-10 or AOS-8 allows authenticated remote attackers to delete any files on the system. Thi...

CVE-2025-37178

MEDIUM CVSS 5.3 Jan 13, 2026

This CVE describes multiple out-of-bounds read vulnerabilities in a system component that handles data buffers. Insufficient validation of buffer size values allows reading beyond intended memory regi...

CVE-2025-37162

MEDIUM CVSS 6.5 Nov 18, 2025

This vulnerability allows authenticated remote attackers to inject malicious commands through the device's command line interface, potentially executing arbitrary operating system commands. It affects...

CVE-2025-37142

MEDIUM CVSS 4.9 Oct 14, 2025

This vulnerability allows authenticated attackers to download arbitrary files from AOS-10 GW and AOS-8 Controller/Mobility Conductor systems via the CLI binary. Organizations using these Aruba network...

CVE-2025-37143

MEDIUM CVSS 4.9 Oct 14, 2025

An authenticated attacker can download arbitrary files from AOS-10 GW and AOS-8 Controller/Mobility Conductor systems through the web management interface. This affects organizations using these Aruba...

CVE-2025-37144

MEDIUM CVSS 4.9 Oct 14, 2025

This vulnerability allows authenticated attackers to download arbitrary files from affected Aruba networking devices through path traversal attacks. It affects AOS-10 Gateway and AOS-8 Controller/Mobi...

CVE-2025-37145

MEDIUM CVSS 4.9 Oct 14, 2025

This vulnerability allows authenticated attackers to download arbitrary files from AOS-10 GW and AOS-8 Controller/Mobility Conductor systems through a low-level interface library. It affects organizat...

CVE-2025-37136

MEDIUM CVSS 6.5 Oct 14, 2025

This vulnerability allows authenticated remote attackers to delete arbitrary files on Aruba AOS-8 Controller/Mobility Conductor systems via the command-line interface. This affects organizations using...

CVE-2025-37137

MEDIUM CVSS 6.5 Oct 14, 2025

This vulnerability allows authenticated remote attackers to delete arbitrary files on Aruba AOS-8 Controller/Mobility Conductor systems through the command-line interface. This affects organizations u...

CVE-2025-37138

MEDIUM CVSS 6.2 Oct 14, 2025

An authenticated command injection vulnerability in AOS-10 GW and AOS-8 Controllers/Mobility Conductor allows attackers with physical access to execute arbitrary commands as privileged users. This aff...

CVE-2025-37140

MEDIUM CVSS 4.9 Oct 14, 2025

This vulnerability allows authenticated attackers to download arbitrary files from AOS-10 GW and AOS-8 Controller/Mobility Conductor systems through the CLI binary. It affects organizations using thes...

CVE-2025-37141

MEDIUM CVSS 4.9 Oct 14, 2025

This vulnerability allows authenticated attackers to download arbitrary files from AOS-10 GW and AOS-8 Controller/Mobility Conductor systems via CLI binary exploits. It affects organizations using the...

CVE-2024-42398

MEDIUM CVSS 5.3 Aug 6, 2024

Multiple unauthenticated Denial-of-Service vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Attackers can exploit these vulnerabilities to disrupt normal Access Point operat...

CVE-2024-42400

MEDIUM CVSS 5.3 Aug 6, 2024

Multiple unauthenticated Denial-of-Service vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation allows attackers to disrupt normal Access Point operation...

CVE-2024-31483

MEDIUM CVSS 4.9 May 14, 2024

An authenticated sensitive information disclosure vulnerability in the CLI service accessed via PAPI protocol allows attackers to read arbitrary files on the underlying operating system. This affects ...

CVE-2024-31481

MEDIUM CVSS 5.3 May 14, 2024

Unauthenticated attackers can cause Denial of Service (DoS) by exploiting vulnerabilities in the CLI service accessed via the PAPI protocol in Aruba/HPE networking products. This allows interruption o...

CVE-2024-31479

MEDIUM CVSS 5.3 May 14, 2024

Unauthenticated attackers can cause Denial of Service (DoS) in Aruba Central Communications service via PAPI protocol, disrupting normal operations. This affects Aruba Central and Mobility Conductor d...

CVE-2024-33516

MEDIUM CVSS 5.3 May 1, 2024

An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol in ArubaOS. This allows attackers to disrupt controller operations without requiring ...

CVE-2024-33518

MEDIUM CVSS 5.3 May 1, 2024

An unauthenticated Denial-of-Service vulnerability in Aruba's Radio Frequency Manager service allows attackers to disrupt service operation via the PAPI protocol. This affects Aruba networking product...

CVE-2024-33514

MEDIUM CVSS 5.3 May 1, 2024

Unauthenticated attackers can cause Denial-of-Service (DoS) in Aruba's AP Management service via the PAPI protocol, disrupting network operations. This affects Aruba wireless access point management s...