Known vulnerabilities in ArubaOS-CX (AOS-CX)

Software CPE: cpe:2.3:h:aruba_networks:aos-cx:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 37
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ArubaOS-CX (AOS-CX) ArubaOS-CX (AOS-CX) is affected by 37 known vulnerabilities: 1 critical, 2 high, 15 medium, 19 low Critical High Medium Low

Vulnerabilities (37)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU123950 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-23817
CWE-601 Low
No
No
10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 12.03.2026 SB2026031234
#VU123949 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-23816
CWE-78 Low
No
No
10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 12.03.2026 SB2026031234
#VU123948 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-23815
CWE-78 Low
No
No
10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 12.03.2026 SB2026031234
#VU123947 - Argument Injection or Modification
CVE-2026-23814
CWE-88 Low
No
No
10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 12.03.2026 SB2026031234
#VU123946 - Weak password recovery mechanism
CVE-2026-23813
CWE-640 High
No
No
10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 12.03.2026 SB2026031234
#VU118622 - Exposure of sensitive information to an unauthorized actor
CVE-2025-37160
CWE-200 Medium
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 19.11.2025 SB2025111932
#VU118621 - Session Fixation
CVE-2025-37159
CWE-384 Low
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 19.11.2025 SB2025111932
#VU118620 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37158
CWE-78 Low
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 19.11.2025 SB2025111932
#VU118619 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37157
CWE-78 Low
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 19.11.2025 SB2025111932
#VU118618 - Improper input validation
CVE-2025-37156
CWE-20 Low
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 19.11.2025 SB2025111932
#VU118617 - Improper Access Control
CVE-2025-37155
CWE-284 Low
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 19.11.2025 SB2025111932
#VU105876 - Improper Access Control
CVE-2025-25042
CWE-284 Medium
No
No
10.10.1150, 10.13.1080, 10.14.1040, 10.15.1005 19.03.2025 SB2025031962
#VU105875 - Exposure of sensitive information to an unauthorized actor
CVE-2025-27080
CWE-200 Low
No
No
10.10.1150, 10.13.1080, 10.14.1040, 10.15.1005 19.03.2025 SB2025031962
#VU104034 - Improper input validation
CVE-2025-26466
CWE-20 Medium
Available
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 18.02.2025 SB2025021815
SB2025021830
SB2025021840
and 25 more
#VU102739 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-12747
CWE-362 Low
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 56 more
#VU102736 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12088
CWE-22 Medium
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 65 more
#VU102734 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12087
CWE-22 Medium
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 74 more
#VU102732 - Exposure of sensitive information to an unauthorized actor
CVE-2024-12086
CWE-200 Medium
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 37 more
#VU102730 - Use of Uninitialized Variable
CVE-2024-12085
CWE-457 Medium
No
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 92 more
#VU102729 - Heap-based Buffer Overflow
CVE-2024-12084
CWE-122 Critical
Available
No
10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 25 more


Showing elements 1 - 20 out of 37