Known vulnerabilities in ArubaOS (AOS) - page 2

Software: ArubaOS (AOS)
Software CPE: cpe:2.3:o:aruba_networks:arubaos:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 174
Public exploits: 6
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ArubaOS (AOS) ArubaOS (AOS) is affected by 174 known vulnerabilities: 52 high, 27 medium, 95 low Critical High Medium Low

Vulnerabilities (174)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118116 - Improper Access Control
CVE-2025-37140
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118114 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37138
CWE-78 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118113 - Improper Access Control
CVE-2025-37137
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118112 - Improper Access Control
CVE-2025-37136
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118111 - Improper Access Control
CVE-2025-37135
CWE-284 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118110 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37134
CWE-78 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118109 - Unrestricted Upload of File with Dangerous Type
CVE-2025-37132
CWE-434 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU118108 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37133
CWE-78 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 05.11.2025 SB2025110525
#VU117362 - Improper input validation
CVE-2025-37148
CWE-20 Medium
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 17.10.2025 SB2025101768
#VU117361 - Protection Mechanism Failure
CVE-2025-37147
CWE-693 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 17.10.2025 SB2025101768
#VU117360 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37146
CWE-78 Low
No
No
8.10.0.19, 8.12.0.6, 8.13.1.0, 10.4.1.9, 10.7.2.1 17.10.2025 SB2025101768
#VU102753 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-23052
CWE-78 Low
No
No
8.10.0.15, 8.12.0.3, 10.4.1.5, 10.7.0.0 15.01.2025 SB2025011501
#VU102752 - Argument Injection or Modification
CVE-2025-23051
CWE-88 Low
No
No
8.10.0.15, 8.12.0.3, 10.4.1.5, 10.7.0.0 14.01.2025 SB2025011501
#VU99887 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-47464
CWE-22 Low
No
No
10.4.1.5, 10.7.0.0 06.11.2024 SB2024110639
#VU99886 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-47463
CWE-78 Low
No
No
10.4.1.5, 10.7.0.0 06.11.2024 SB2024110639
#VU99885 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-47462
CWE-78 Low
No
No
10.4.1.5, 10.7.0.0 06.11.2024 SB2024110639
#VU99868 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-47461
CWE-78 Low
No
No
10.4.1.5, 10.7.0.0 06.11.2024 SB2024110639
#VU99867 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-47460
CWE-78 High
No
No
10.4.1.5, 10.7.0.0 06.11.2024 SB2024110639
#VU99866 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-42509
CWE-78 High
No
No
10.4.1.5, 10.7.0.0 06.11.2024 SB2024110639
#VU97736 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-42505
CWE-78 High
No
No
8.10.0.14, 8.12.0.2, 10.4.1.4, 10.6.0.3, 10.7.0.0 26.09.2024 SB2024092677


Showing elements 21 - 40 out of 174