📦 Instantos

by Hp

🔍 What is Instantos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-42394

CRITICAL CVSS 9.8 Aug 6, 2024

This vulnerability in the Soft AP Daemon Service allows unauthenticated remote attackers to execute arbitrary commands on affected systems, leading to complete system compromise. It affects HPE Aruba ...

CVE-2024-31473

CRITICAL CVSS 9.8 May 14, 2024

This critical vulnerability in Aruba access points allows unauthenticated attackers to execute arbitrary commands with root privileges by sending malicious packets to port 8211. It affects ArubaOS 10 ...

CVE-2024-31469

CRITICAL CVSS 9.8 May 14, 2024

CVE-2024-31469 is a critical buffer overflow vulnerability in Aruba's Central Communications service that allows unauthenticated attackers to execute arbitrary code with privileged access by sending m...

CVE-2024-31471

CRITICAL CVSS 9.8 May 14, 2024

CVE-2024-31471 is a critical command injection vulnerability in Aruba's Central Communications service that allows unauthenticated attackers to execute arbitrary code with privileged access by sending...

CVE-2024-31467

CRITICAL CVSS 9.8 May 14, 2024

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2024-31466

CRITICAL CVSS 9.8 May 14, 2024

CVE-2024-31466 is a critical buffer overflow vulnerability in Aruba's Access Point management protocol (PAPI) that allows unauthenticated attackers to execute arbitrary code with privileged access by ...

CVE-2023-45614

CRITICAL CVSS 9.8 Nov 14, 2023

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2023-45616

CRITICAL CVSS 9.8 Nov 14, 2023

This CVE describes a critical buffer overflow vulnerability in Aruba's AirWave client service that allows unauthenticated attackers to execute arbitrary code with privileged access by sending speciall...

CVE-2023-35980

CRITICAL CVSS 9.8 Jul 25, 2023

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2023-35982

CRITICAL CVSS 9.8 Jul 25, 2023

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2023-22783

CRITICAL CVSS 9.8 May 8, 2023

CVE-2023-22783 is a critical buffer overflow vulnerability in Aruba's PAPI protocol that allows unauthenticated attackers to execute arbitrary code with privileged access on affected Aruba access poin...

CVE-2023-22785

CRITICAL CVSS 9.8 May 8, 2023

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2023-22779

CRITICAL CVSS 9.8 May 8, 2023

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2023-22781

CRITICAL CVSS 9.8 May 8, 2023

This critical vulnerability allows unauthenticated attackers to execute arbitrary code with privileged access on Aruba access points by sending specially crafted packets to UDP port 8211. It affects A...

CVE-2024-31477

HIGH CVSS 7.2 May 14, 2024

This CVE describes authenticated command injection vulnerabilities in HPE Aruba Networking products that allow attackers with CLI access to execute arbitrary commands as privileged users on the underl...

CVE-2024-31475

HIGH CVSS 8.2 May 14, 2024

This vulnerability allows attackers to delete arbitrary files on Aruba Access Points through the Central Communications service via PAPI. Successful exploitation can disrupt operations and compromise ...

CVE-2023-45624

HIGH CVSS 7.5 Nov 14, 2023

An unauthenticated Denial-of-Service vulnerability in the soft AP daemon accessed via PAPI protocol allows attackers to disrupt affected access points without authentication. This affects Aruba access...

CVE-2023-45620

HIGH CVSS 7.5 Nov 14, 2023

Unauthenticated attackers can cause denial-of-service conditions in Aruba access points by exploiting vulnerabilities in the CLI service accessed via PAPI protocol. This affects Aruba access points wi...

CVE-2023-45622

HIGH CVSS 7.5 Nov 14, 2023

Unauthenticated attackers can exploit vulnerabilities in the BLE daemon service via the PAPI protocol to cause Denial-of-Service (DoS) on affected Aruba access points. This disrupts normal wireless ne...

CVE-2023-45618

HIGH CVSS 8.2 Nov 14, 2023

This vulnerability in Aruba's AirWave client service allows attackers to delete arbitrary files on the operating system via the PAPI protocol. This could disrupt normal operations and compromise syste...

CVE-2023-22787

HIGH CVSS 7.5 May 8, 2023

An unauthenticated Denial of Service vulnerability in Aruba's PAPI protocol allows attackers to disrupt affected access points without credentials. This affects Aruba InstantOS and ArubaOS 10 systems,...

CVE-2023-22789

HIGH CVSS 7.2 May 8, 2023

This CVE describes authenticated command injection vulnerabilities in Aruba InstantOS and ArubaOS 10 command line interfaces. Attackers with authenticated access can execute arbitrary commands as priv...

CVE-2024-42398

MEDIUM CVSS 5.3 Aug 6, 2024

Multiple unauthenticated Denial-of-Service vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Attackers can exploit these vulnerabilities to disrupt normal Access Point operat...

CVE-2024-42400

MEDIUM CVSS 5.3 Aug 6, 2024

Multiple unauthenticated Denial-of-Service vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation allows attackers to disrupt normal Access Point operation...

CVE-2024-42396

MEDIUM CVSS 5.3 Aug 6, 2024

Multiple unauthenticated Denial-of-Service vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Attackers can exploit these vulnerabilities to disrupt normal A...

CVE-2024-31483

MEDIUM CVSS 4.9 May 14, 2024

An authenticated sensitive information disclosure vulnerability in the CLI service accessed via PAPI protocol allows attackers to read arbitrary files on the underlying operating system. This affects ...

CVE-2024-31481

MEDIUM CVSS 5.3 May 14, 2024

Unauthenticated attackers can cause Denial of Service (DoS) by exploiting vulnerabilities in the CLI service accessed via the PAPI protocol in Aruba/HPE networking products. This allows interruption o...

CVE-2024-31479

MEDIUM CVSS 5.3 May 14, 2024

Unauthenticated attackers can cause Denial of Service (DoS) in Aruba Central Communications service via PAPI protocol, disrupting normal operations. This affects Aruba Central and Mobility Conductor d...