Known vulnerabilities in ArubaOS (AOS) 8.6.0.2

Software: ArubaOS (AOS)
Version: 8.6.0.2
Software CPE: cpe:2.3:o:aruba_networks:arubaos:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 95
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting ArubaOS (AOS) version 8.6.0.2 ArubaOS (AOS) 8.6.0.2 is affected by 95 vulnerabilities: 13 high, 12 medium, 70 low Critical High Medium Low

Vulnerabilities (95)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121590 - Out-of-bounds read
CVE-2025-37179
CWE-125 Medium
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121589 - Out-of-bounds read
CVE-2025-37178
CWE-125 Medium
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121588 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37177
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1, 10.4.1.10, 10.7.2.2 15.01.2026 SB2026011551
#VU121587 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37176
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121586 - Unrestricted Upload of File with Dangerous Type
CVE-2025-37175
CWE-434 Low
No
No
8.10.0.21, 8.13.1.1, 10.4.1.10, 10.7.2.2 15.01.2026 SB2026011551
#VU121585 - Unrestricted Upload of File with Dangerous Type
CVE-2025-37174
CWE-434 Low
No
No
8.10.0.21, 8.13.1.1, 10.4.1.10, 10.7.2.2 15.01.2026 SB2026011551
#VU121584 - Improper input validation
CVE-2025-37173
CWE-20 Low
No
No
8.10.0.21, 8.13.1.1, 10.4.1.10, 10.7.2.2 15.01.2026 SB2026011551
#VU121580 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37171
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121581 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37172
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121579 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37170
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121575 - Missing Authorization
CVE-2025-37168
CWE-862 Medium
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU118116 - Improper Access Control
CVE-2025-37140
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118115 - Resource exhaustion
CVE-2025-37139
CWE-400 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118114 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37138
CWE-78 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118113 - Improper Access Control
CVE-2025-37137
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118112 - Improper Access Control
CVE-2025-37136
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118111 - Improper Access Control
CVE-2025-37135
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118110 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37134
CWE-78 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118109 - Unrestricted Upload of File with Dangerous Type
CVE-2025-37132
CWE-434 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118108 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37133
CWE-78 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525


Showing elements 1 - 20 out of 95