Skip to content
VulniPulse

HPE Aruba Networking AOS-8 Mobility Controllers Vulnerabilities & Security Advisories

38 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as AOS-8 Mobility Controllers, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 24 high, 13 medium, 1 low.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba AOS-8 Mobility Controllers advisories

High7.2Aruba

High [CVE-2024-42503] ArubaOS: Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI).

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a priviledge user on the underlying operating system.

CVE-2024-42503
AOS-8 MobilityWireless & ControllersArubaOS
Sep 17, 2024
High7.2Aruba

High [CVE-2024-42502] ArubaOS: Authenticated command injection vulnerability exists in the ArubaOS command line interface.

Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underlying operating system.

CVE-2024-42502
AOS-8 MobilityWireless & ControllersArubaOS
Sep 17, 2024
High7.2Aruba

High [CVE-2024-42501] ArubaOS: authenticated Path Traversal vulnerabilities exists in the ArubaOS.

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary code or install implants.

CVE-2024-42501
AOS-8 MobilityWireless & ControllersArubaOS
Sep 17, 2024
High7.2Aruba

High [CVE-2024-25613] ArubaOS: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2024-25613
AOS-8 MobilityWireless & ControllersArubaOS
Mar 5, 2024

← All Aruba advisories