HPE / Aruba ArubaOS
Our sources currently list 227 known vulnerabilities affecting HPE / Aruba ArubaOS. 39 are rated critical severity.
Last updated: 22 July 2026, 20:35 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2017-14491 | Critical (9.8) | Elevated likelihood (85%) | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | |
| CVE-2018-7081 | Critical (9.8) | No exploitation reported | A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic … | |
| CVE-2016-2031 | Critical (9.8) | No exploitation reported | Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which cou… | |
| CVE-2020-24633 | Critical (9.8) | No exploitation reported | There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networ… | |
| CVE-2021-37717 | High (7.2) | No exploitation reported | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior… | |
| CVE-2021-37718 | High (7.2) | No exploitation reported | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior… | |
| CVE-2021-37720 | High (7.2) | No exploitation reported | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior… | |
| CVE-2021-37721 | High (7.2) | No exploitation reported | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior… | |
| CVE-2021-37722 | High (7.2) | No exploitation reported | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior… | |
| CVE-2021-37723 | High (7.2) | No exploitation reported | A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released p… | |
| CVE-2021-37724 | High (7.2) | No exploitation reported | A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released p… | |
| CVE-2021-37719 | High (7.2) | No exploitation reported | A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior… | |
| CVE-2016-2032 | High (7.5) | No exploitation reported | A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a ma… | |
| CVE-2021-37716 | Critical (9.8) | No exploitation reported | A remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.2,… | |
| CVE-2008-2273 | Critical (9.0) | No exploitation reported | Unspecified vulnerability in the TACACS authentication component in Aruba Mobility Controller 3.1.x, 3.2.x, and 3.3.x allows remote authenticated users to gain privileges via unkno… | |
| CVE-2019-5315 | High (7.2) | No exploitation reported | A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating… | |
| CVE-2023-45614 | Critical (9.8) | No exploitation reported | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to th… | |
| CVE-2023-45615 | Critical (9.8) | No exploitation reported | There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to th… | |
| CVE-2023-45616 | Critical (9.8) | No exploitation reported | There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets dest… | |
| CVE-2014-7299 | High (7.5) | No exploitation reported | Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authenti… | |
| CVE-2020-24634 | Critical (9.8) | No exploitation reported | An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of acce… | |
| CVE-2023-45625 | High (7.2) | No exploitation reported | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbi… | |
| CVE-2008-7023 | Critical (10.0) | No exploitation reported | Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to… | |
| CVE-2023-22747 | Critical (9.8) | No exploitation reported | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Netwo… | |
| CVE-2023-22748 | Critical (9.8) | No exploitation reported | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Netw… | |
| CVE-2023-22749 | Critical (9.8) | No exploitation reported | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Netw… | |
| CVE-2023-22750 | Critical (9.8) | No exploitation reported | There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Netw… | |
| CVE-2023-22788 | High (7.2) | No exploitation reported | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result… | |
| CVE-2023-22790 | High (7.2) | No exploitation reported | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result… | |
| CVE-2022-37897 | Critical (9.8) | No exploitation reported | There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP man… | |
| CVE-2022-37899 | High (7.2) | No exploitation reported | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi… | |
| CVE-2022-37900 | High (7.2) | No exploitation reported | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi… | |
| CVE-2022-37901 | High (7.2) | No exploitation reported | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi… | |
| CVE-2022-37902 | High (7.2) | No exploitation reported | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi… | |
| CVE-2023-22789 | High (7.2) | No exploitation reported | Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result… | |
| CVE-2024-31473 | Critical (9.8) | No exploitation reported | There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets … | |
| CVE-2022-37887 | Critical (9.8) | No exploitation reported | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to … | |
| CVE-2022-37889 | Critical (9.8) | No exploitation reported | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to … | |
| CVE-2023-22758 | High (7.2) | No exploitation reported | Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability t… | |
| CVE-2023-22759 | High (7.2) | No exploitation reported | Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability t… | |
| CVE-2023-22760 | High (7.2) | No exploitation reported | Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability t… | |
| CVE-2023-22761 | High (7.2) | No exploitation reported | Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability t… | |
| CVE-2023-35980 | Critical (9.8) | No exploitation reported | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to … | |
| CVE-2023-35981 | Critical (9.8) | No exploitation reported | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to … | |
| CVE-2023-35982 | Critical (9.8) | No exploitation reported | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to … | |
| CVE-2024-31471 | Critical (9.8) | No exploitation reported | There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted pa… | |
| CVE-2024-31472 | Critical (9.8) | No exploitation reported | There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets d… | |
| CVE-2022-37912 | High (7.2) | No exploitation reported | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi… | |
| CVE-2022-37888 | Critical (9.8) | No exploitation reported | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to … | |
| CVE-2023-35972 | High (7.2) | No exploitation reported | An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability t… |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
Running HPE / Aruba ArubaOS?
Our Newcastle team can audit your HPE / Aruba estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
