Known vulnerabilities in ArubaOS (AOS)

Software: ArubaOS (AOS)
Software CPE: cpe:2.3:o:aruba_networks:arubaos:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 174
Public exploits: 6
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ArubaOS (AOS) ArubaOS (AOS) is affected by 174 known vulnerabilities: 52 high, 27 medium, 95 low Critical High Medium Low

Vulnerabilities (174)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121590 - Out-of-bounds read
CVE-2025-37179
CWE-125 Medium
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121589 - Out-of-bounds read
CVE-2025-37178
CWE-125 Medium
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121588 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37177
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1, 10.4.1.10, 10.7.2.2 15.01.2026 SB2026011551
#VU121587 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37176
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121586 - Unrestricted Upload of File with Dangerous Type
CVE-2025-37175
CWE-434 Low
No
No
8.10.0.21, 8.13.1.1, 10.4.1.10, 10.7.2.2 15.01.2026 SB2026011551
#VU121585 - Unrestricted Upload of File with Dangerous Type
CVE-2025-37174
CWE-434 Low
No
No
8.10.0.21, 8.13.1.1, 10.4.1.10, 10.7.2.2 15.01.2026 SB2026011551
#VU121584 - Improper input validation
CVE-2025-37173
CWE-20 Low
No
No
8.10.0.21, 8.13.1.1, 10.4.1.10, 10.7.2.2 15.01.2026 SB2026011551
#VU121580 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37171
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121581 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37172
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121579 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37170
CWE-78 Low
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU121578 - Stack-based buffer overflow
CVE-2025-37169
CWE-121 Low
No
No
10.4.1.10, 10.7.2.2 15.01.2026 SB2026011551
#VU121575 - Missing Authorization
CVE-2025-37168
CWE-862 Medium
No
No
8.10.0.21, 8.13.1.1 15.01.2026 SB2026011551
#VU118612 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37162
CWE-78 Low
No
No
10.7.2.0 19.11.2025 SB2025111907
#VU118611 - Improper input validation
CVE-2025-37161
CWE-20 Medium
No
No
10.7.2.0 19.11.2025 SB2025111907
#VU118121 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-37145
CWE-22 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118120 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-37144
CWE-22 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118119 - Improper Access Control
CVE-2025-37143
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118118 - Improper Access Control
CVE-2025-37142
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118117 - Improper Access Control
CVE-2025-37141
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118115 - Resource exhaustion
CVE-2025-37139
CWE-400 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525


Showing elements 1 - 20 out of 174