Known vulnerabilities in ArubaOS-CX (AOS-CX)
Vendor:
Aruba Networks
Software:
ArubaOS-CX (AOS-CX)
Software CPE:
cpe:2.3:h:aruba_networks:aos-cx:*:*:*:*:*:*:*:*
Total vulnerabilities:
37
Public exploits:
5
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.13.1160
10.16.1020
10.17.0001
10.10.1180
10.13.1161
10.16.1030
10.17.1001
10.10.1170
10.13.1101
10.14.1060
10.15.1030
10.16.1006
10.10.1160
10.13.1090
10.14.1050
10.15.1020
10.16.1000
10.15.1001
10.10.1150
10.13.1080
10.14.1040
10.15.1005
10.10.1140
10.13.1040
10.14.1010
10.10.1131
10.13.1031
10.14.0007
10.10.1110
10.12.1030
10.13.1010
10.06.0240
10.10.1030
10.11.0001
10.06.0200
10.08.1060
10.09.1020
10.06.0220
10.08.1080
10.09.1040
10.10.0002
10.06.0210
10.08.1070
10.09.1030
10.10.1000
Vulnerabilities (37)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU123950 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2026-23817 |
CWE-601 | Low | 10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 | 12.03.2026 |
SB2026031234 |
||
| #VU123949 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-23816 |
CWE-78 | Low | 10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 | 12.03.2026 |
SB2026031234 |
||
| #VU123948 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-23815 |
CWE-78 | Low | 10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 | 12.03.2026 |
SB2026031234 |
||
| #VU123947 - Argument Injection or Modification CVE-2026-23814 |
CWE-88 | Low | 10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 | 12.03.2026 |
SB2026031234 |
||
| #VU123946 - Weak password recovery mechanism CVE-2026-23813 |
CWE-640 | High | 10.10.1180, 10.13.1161, 10.16.1030, 10.17.1001 | 12.03.2026 |
SB2026031234 |
||
| #VU118622 - Exposure of sensitive information to an unauthorized actor CVE-2025-37160 |
CWE-200 | Medium | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 19.11.2025 |
SB2025111932 |
||
| #VU118621 - Session Fixation CVE-2025-37159 |
CWE-384 | Low | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 19.11.2025 |
SB2025111932 |
||
| #VU118620 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2025-37158 |
CWE-78 | Low | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 19.11.2025 |
SB2025111932 |
||
| #VU118619 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2025-37157 |
CWE-78 | Low | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 19.11.2025 |
SB2025111932 |
||
| #VU118618 - Improper input validation CVE-2025-37156 |
CWE-20 | Low | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 19.11.2025 |
SB2025111932 |
||
| #VU118617 - Improper Access Control CVE-2025-37155 |
CWE-284 | Low | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 19.11.2025 |
SB2025111932 |
||
| #VU105876 - Improper Access Control CVE-2025-25042 |
CWE-284 | Medium | 10.10.1150, 10.13.1080, 10.14.1040, 10.15.1005 | 19.03.2025 |
SB2025031962 |
||
| #VU105875 - Exposure of sensitive information to an unauthorized actor CVE-2025-27080 |
CWE-200 | Low | 10.10.1150, 10.13.1080, 10.14.1040, 10.15.1005 | 19.03.2025 |
SB2025031962 |
||
| #VU104034 - Improper input validation CVE-2025-26466 |
CWE-20 | Medium | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 18.02.2025 |
SB2025021815 SB2025021830 SB2025021840 and 25 more |
||
| #VU102739 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-12747 |
CWE-362 | Low | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 14.01.2025 |
SB2025011495 SB2025011504 SB2025011530 and 56 more |
||
| #VU102736 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-12088 |
CWE-22 | Medium | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 14.01.2025 |
SB2025011495 SB2025011504 SB2025011530 and 65 more |
||
| #VU102734 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-12087 |
CWE-22 | Medium | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 14.01.2025 |
SB2025011495 SB2025011504 SB2025011530 and 74 more |
||
| #VU102732 - Exposure of sensitive information to an unauthorized actor CVE-2024-12086 |
CWE-200 | Medium | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 14.01.2025 |
SB2025011495 SB2025011504 SB2025011530 and 37 more |
||
| #VU102730 - Use of Uninitialized Variable CVE-2024-12085 |
CWE-457 | Medium | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 14.01.2025 |
SB2025011495 SB2025011504 SB2025011530 and 92 more |
||
| #VU102729 - Heap-based Buffer Overflow CVE-2024-12084 |
CWE-122 | Critical | 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006 | 14.01.2025 |
SB2025011495 SB2025011504 SB2025011530 and 25 more |
Showing elements 1 - 20 out of 37