Arubanetworks
Arubanetworks Airwave: vulnerabilidades y CVE
Arubanetworks Airwave tiene 36 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE36
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-37163 | Alta (7.2) | 0.99% | — | 18 nov 2025 | A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating… |
| CVE-2023-4896 | Media (6.5) | 0.44% | — | 17 oct 2023 | A vulnerability exists which allows an authenticated attacker to access sensitive information on the AirWave Management Platform web-based management interface. Successful exploitation allows the attacker to gain access… |
| CVE-2015-2202 | Alta (7.2) | 0.85% | — | 5 sept 2023 | Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS. |
| CVE-2015-2201 | Alta (7.2) | 1.2% | — | 5 sept 2023 | Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users. |
| CVE-2022-37918 | Alta (8.1) | 0.79% | — | 8 dic 2022 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited… |
| CVE-2022-37917 | Alta (8.1) | 0.79% | — | 8 dic 2022 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited… |
| CVE-2022-37916 | Alta (8.1) | 0.79% | — | 8 dic 2022 | Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited… |
| CVE-2021-37715 | Media (4.8) | 0.46% | — | 26 ago 2021 | A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.13.0. Aruba has released upgrades for the Aruba AirWave Management Platform that address… |
| CVE-2021-29137 | Media (6.1) | 0.75% | — | 29 abr 2021 | A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security… |
| CVE-2021-25167 | Alta (8.8) | 1.5% | — | 29 abr 2021 | A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security… |
| CVE-2021-25166 | Alta (8.8) | 1.5% | — | 29 abr 2021 | A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security… |
| CVE-2021-25163 | Alta (8.1) | 1.2% | — | 29 abr 2021 | A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security… |
| CVE-2021-25165 | Alta (8.1) | 1.2% | — | 28 abr 2021 | A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security… |
| CVE-2021-25164 | Media (6.5) | 1.3% | — | 28 abr 2021 | A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security… |
| CVE-2021-25152 | Alta (7.2) | 1.2% | — | 28 abr 2021 | A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security… |
| CVE-2021-25154 | Alta (7.5) | 1.0% | — | 28 abr 2021 | A remote escalation of privilege vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security… |
| CVE-2021-25153 | Alta (8.1) | 1.1% | — | 28 abr 2021 | A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. |
| CVE-2021-25151 | Alta (8.8) | 12% | — | 28 abr 2021 | A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security… |
| CVE-2021-25147 | Alta (8.1) | 1.3% | — | 28 abr 2021 | A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this… |
| CVE-2021-26971 | Media (6.3) | 1.3% | — | 5 mar 2021 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could… |
| CVE-2021-26970 | Media (6.3) | 1.4% | — | 5 mar 2021 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could… |
| CVE-2021-26969 | Media (6.5) | 1.5% | — | 5 mar 2021 | A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Due to improper restrictions on XML entities a… |
| CVE-2021-26968 | Media (4.8) | 0.66% | — | 5 mar 2021 | A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave… |
| CVE-2021-26967 | Media (6.1) | 0.83% | — | 5 mar 2021 | A remote reflected cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the web-based management interface of AirWave could allow… |
| CVE-2021-26966 | Media (6.5) | 1.2% | — | 5 mar 2021 | A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote… |
| CVE-2021-26965 | Media (6.5) | 1.2% | — | 5 mar 2021 | A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote… |
| CVE-2021-26964 | Alta (7.1) | 0.99% | — | 5 mar 2021 | A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an… |
| CVE-2021-26963 | Alta (7.2) | 3.0% | — | 5 mar 2021 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated… |
| CVE-2021-26962 | Alta (7.2) | 3.2% | — | 5 mar 2021 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated… |
| CVE-2021-26961 | Alta (8.8) | 0.63% | — | 5 mar 2021 | A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.