Arubanetworks
Arubanetworks Sd-wan: vulnerabilidades y CVE
Arubanetworks Sd-wan tiene 89 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 16 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE89
Últimos 12 meses26
Críticas16
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-44871 | Alta (8.8) | 1.4% | — | 12 may 2026 | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an… |
| CVE-2026-44873 | Media (5.4) | 0.23% | — | 12 may 2026 | A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are… |
| CVE-2026-44872 | Alta (7.2) | 1.2% | — | 12 may 2026 | A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arbitrary files on the… |
| CVE-2026-44870 | Alta (8.8) | 1.4% | — | 12 may 2026 | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an… |
| CVE-2026-44869 | Alta (8.8) | 1.4% | — | 12 may 2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to… |
| CVE-2026-44868 | Alta (8.8) | 1.4% | — | 12 may 2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to… |
| CVE-2026-44867 | Alta (8.8) | 1.4% | — | 12 may 2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to… |
| CVE-2026-44866 | Alta (8.8) | 1.4% | — | 12 may 2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to… |
| CVE-2026-44865 | Alta (7.2) | 1.5% | — | 12 may 2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to… |
| CVE-2026-44864 | Alta (7.2) | 0.58% | — | 12 may 2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative… |
| CVE-2026-44863 | Alta (7.2) | 0.58% | — | 12 may 2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative… |
| CVE-2026-44862 | Alta (7.2) | 0.58% | — | 12 may 2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative… |
| CVE-2026-44861 | Alta (7.2) | 0.58% | — | 12 may 2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative… |
| CVE-2026-44860 | Alta (7.2) | 0.58% | — | 12 may 2026 | SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative… |
| CVE-2026-44859 | Alta (7.2) | 0.62% | — | 12 may 2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with… |
| CVE-2026-44858 | Alta (7.2) | 0.62% | — | 12 may 2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with… |
| CVE-2026-44857 | Alta (7.2) | 0.62% | — | 12 may 2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with… |
| CVE-2026-44856 | Alta (7.2) | 0.62% | — | 12 may 2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with… |
| CVE-2026-44855 | Alta (7.2) | 0.62% | — | 12 may 2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with… |
| CVE-2026-44854 | Alta (7.2) | 1.6% | — | 12 may 2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the… |
| CVE-2026-44853 | Alta (7.2) | 1.6% | — | 12 may 2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the… |
| CVE-2026-44852 | Alta (7.2) | 0.61% | — | 12 may 2026 | An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker… |
| CVE-2026-23827 | Alta (7.5) | 0.53% | — | 12 may 2026 | A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could… |
| CVE-2026-23826 | Alta (7.5) | 0.40% | — | 12 may 2026 | A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device,… |
| CVE-2026-23825 | Alta (7.5) | 0.33% | — | 12 may 2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected… |
| CVE-2026-23824 | Alta (7.5) | 0.33% | — | 12 may 2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected… |
| CVE-2024-26305 | Crítica (9.8) | 15% | — | 1 may 2024 | There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point… |
| CVE-2023-22778 | Media (4.8) | 0.47% | — | 1 mar 2023 | A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could… |
| CVE-2023-22777 | Media (6.5) | 0.59% | — | 1 mar 2023 | An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying… |
| CVE-2023-22776 | Media (4.9) | 0.71% | — | 1 mar 2023 | An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.