HPE / Aruba ArubaOS

Our sources currently list 227 known vulnerabilities affecting HPE / Aruba ArubaOS. 39 are rated critical severity.

Last updated: 22 July 2026, 20:35 AEST

No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.

Known vulnerabilities in HPE / Aruba ArubaOS, highest risk first.Showing the 50 highest-risk of 227 total.
CVESeverityExploitationPublishedSummary
CVE-2017-14491Critical (9.8)Elevated likelihood (85%)Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
CVE-2018-7081Critical (9.8)No exploitation reportedA remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic …
CVE-2016-2031Critical (9.8)No exploitation reportedMultiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which cou…
CVE-2020-24633Critical (9.8)No exploitation reportedThere are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networ…
CVE-2021-37717High (7.2)No exploitation reportedA remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior…
CVE-2021-37718High (7.2)No exploitation reportedA remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior…
CVE-2021-37720High (7.2)No exploitation reportedA remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior…
CVE-2021-37721High (7.2)No exploitation reportedA remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior…
CVE-2021-37722High (7.2)No exploitation reportedA remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior…
CVE-2021-37723High (7.2)No exploitation reportedA remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released p…
CVE-2021-37724High (7.2)No exploitation reportedA remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released p…
CVE-2021-37719High (7.2)No exploitation reportedA remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior…
CVE-2016-2032High (7.5)No exploitation reportedA vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a ma…
CVE-2021-37716Critical (9.8)No exploitation reportedA remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.2,…
CVE-2008-2273Critical (9.0)No exploitation reportedUnspecified vulnerability in the TACACS authentication component in Aruba Mobility Controller 3.1.x, 3.2.x, and 3.3.x allows remote authenticated users to gain privileges via unkno…
CVE-2019-5315High (7.2)No exploitation reportedA command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating…
CVE-2023-45614Critical (9.8)No exploitation reportedThere are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to th…
CVE-2023-45615Critical (9.8)No exploitation reportedThere are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to th…
CVE-2023-45616Critical (9.8)No exploitation reportedThere is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets dest…
CVE-2014-7299High (7.5)No exploitation reportedUnspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authenti…
CVE-2020-24634Critical (9.8)No exploitation reportedAn attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of acce…
CVE-2023-45625High (7.2)No exploitation reportedMultiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbi…
CVE-2008-7023Critical (10.0)No exploitation reportedAruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to…
CVE-2023-22747Critical (9.8)No exploitation reportedThere are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Netwo…
CVE-2023-22748Critical (9.8)No exploitation reported There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Netw…
CVE-2023-22749Critical (9.8)No exploitation reported There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Netw…
CVE-2023-22750Critical (9.8)No exploitation reported There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Netw…
CVE-2023-22788High (7.2)No exploitation reportedMultiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result…
CVE-2023-22790High (7.2)No exploitation reportedMultiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result…
CVE-2022-37897Critical (9.8)No exploitation reportedThere is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP man…
CVE-2022-37899High (7.2)No exploitation reportedAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi…
CVE-2022-37900High (7.2)No exploitation reportedAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi…
CVE-2022-37901High (7.2)No exploitation reportedAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi…
CVE-2022-37902High (7.2)No exploitation reportedAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi…
CVE-2023-22789High (7.2)No exploitation reportedMultiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result…
CVE-2024-31473Critical (9.8)No exploitation reportedThere is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets …
CVE-2022-37887Critical (9.8)No exploitation reportedThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …
CVE-2022-37889Critical (9.8)No exploitation reportedThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …
CVE-2023-22758High (7.2)No exploitation reportedAuthenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability t…
CVE-2023-22759High (7.2)No exploitation reportedAuthenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability t…
CVE-2023-22760High (7.2)No exploitation reportedAuthenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability t…
CVE-2023-22761High (7.2)No exploitation reportedAuthenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability t…
CVE-2023-35980Critical (9.8)No exploitation reportedThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …
CVE-2023-35981Critical (9.8)No exploitation reportedThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …
CVE-2023-35982Critical (9.8)No exploitation reportedThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …
CVE-2024-31471Critical (9.8)No exploitation reportedThere is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted pa…
CVE-2024-31472Critical (9.8)No exploitation reportedThere are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets d…
CVE-2022-37912High (7.2)No exploitation reportedAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbi…
CVE-2022-37888Critical (9.8)No exploitation reportedThere are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …
CVE-2023-35972High (7.2)No exploitation reportedAn authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability t…

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

Running HPE / Aruba ArubaOS?

Our Newcastle team can audit your HPE / Aruba estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.