Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
airwave vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2023-4896
A vulnerability exists which allows an authenticated malicious user to access sensitive information on the AirWave Management Platform web-based management interface. Successful exploitation allows the malicious user to gain access to some data that could be further exploited to ...
Arubanetworks Airwave
7.2
CVSSv3
CVE-2019-5323
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.
Arubanetworks Airwave
4.8
CVSSv3
CVE-2021-37715
A remote cross-site scripting (XSS) vulnerability exists in Aruba AirWave Management Platform version(s): before 8.2.13.0. Aruba has released upgrades for the Aruba AirWave Management Platform that address this security vulnerability.
Arubanetworks Airwave
8.8
CVSSv3
CVE-2016-8526
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can ...
Hp Airwave
1 EDB exploit
6.1
CVSSv3
CVE-2016-8527
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative ...
Hp Airwave
1 EDB exploit
NA
CVE-2014-8368
The web interface in Aruba Networks AirWave prior to 7.7.14 and 8.x prior to 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors.
Arubanetworks Airwave
8.8
CVSSv3
CVE-2021-26961
A remote unauthenticated cross-site request forgery (csrf) vulnerability exists in Aruba AirWave Management Platform version(s): before 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote malicious user to conduct a CSRF a...
Arubanetworks Airwave
6.5
CVSSv3
CVE-2021-26965
A remote authenticated sql injection vulnerability exists in Aruba AirWave Management Platform version(s): before 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote malicious user to conduct SQL injection attacks against the AirWave insta...
Arubanetworks Airwave
6.5
CVSSv3
CVE-2021-26966
A remote authenticated sql injection vulnerability exists in Aruba AirWave Management Platform version(s): before 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote malicious user to conduct SQL injection attacks against the AirWave insta...
Arubanetworks Airwave
8.8
CVSSv3
CVE-2021-25167
A remote unauthorized access vulnerability exists in Aruba AirWave Management Platform version(s) before 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
Arubanetworks Airwave
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-38002
CVE-2006-4304
CVE-2024-4336
CVE-2024-33437
CVE-2024-4340
CVE-2024-27956
privilege
insecure direct object reference
XSS
item search icon">CVE-2024-25938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »