Skip to content
VulniPulse

HPE Aruba Networking AOS-10 Gateways & APs Vulnerabilities & Security Advisories

36 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as AOS-10 Gateways & APs, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 24 high, 12 medium.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba AOS-10 Gateways & APs advisories

High7.2Aruba

High [CVE-2025-27082] Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8…

Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system.

CVE-2025-27082
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Apr 8, 2025
High7.2Aruba

High [CVE-2025-23051] authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10…

An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.

CVE-2025-23051
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
Jan 14, 2025
High7.2Aruba

High [CVE-2024-47463] AOS-10: arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface.

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.

CVE-2024-47463
AOS-10Instant APWireless & ControllersInstant
Nov 5, 2024
High7.2Aruba

High [CVE-2024-47461] AOS-10: authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface.

An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying host operating system.

CVE-2024-47461
AOS-10Instant APWireless & ControllersInstant
Nov 5, 2024

← All Aruba advisories