Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Aruba Access Points running InstantOS and ArubaOS 10 — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Aruba Access Points running InstantOS and ArubaOS 10, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security vulnerabilities affecting Aruba Access Points operating on InstantOS and ArubaOS 10 firmware platforms. It specifically focuses on weaknesses such as remote code execution, privilege escalation, and information disclosure that have been identified within these specific software environments. The content herein aggregates data from multiple sources to provide a comprehensive view of the threat landscape associated with these network hardware and software combinations. The collection includes documented vulnerabilities spanning from the early release of ArubaOS 10 through the latest supported versions of InstantOS. This range ensures that administrators can assess risks for both legacy deployments and modern infrastructure setups. By consolidating this information, the page aims to reduce the fragmentation of security data across various vendor announcements and third-party trackers. Visitors to this resource can track vendor advisories to understand how Aruba Networks addresses specific flaws as they emerge. Users can also delve into the mechanics of specific weakness classes to better comprehend the underlying technical issues, such as buffer overflows or input validation failures. Furthermore, the page allows for looking up a product's vulnerability history, enabling security teams to review past incidents and evaluate the long-term stability and security posture of their deployed access points. This historical context is crucial for patch management strategies and risk assessment procedures, helping organizations prioritize remediation efforts based on severity and exploitability.

Vendor: Hewlett Packard Enterprise (HPE)

CVE IDTitleCVSSSeverityPublished
CVE-2023-35982 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-07-25
CVE-2023-35981 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-07-25
CVE-2023-35980 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-07-25
CVE-2023-22791 Aruba InstantOS and ArubaOS 10 Sensitive Information Disclosure 5.4 Medium2023-05-08
CVE-2023-22790 Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface 7.2 High2023-05-08
CVE-2023-22789 Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface 7.2 High2023-05-08
CVE-2023-22788 Authenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line Interface 7.2 High2023-05-08
CVE-2023-22787 Unauthenticated Denial of Service (DoS) in Aruba InstantOS or ArubaOS 10 Service Accessed via the PAPI Protocol 7.5 High2023-05-08
CVE-2023-22786 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-05-08
CVE-2023-22785 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-05-08
CVE-2023-22784 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-05-08
CVE-2023-22783 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-05-08
CVE-2023-22782 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-05-08
CVE-2023-22781 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-05-08
CVE-2023-22780 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-05-08
CVE-2023-22779 Unauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI Protocol 9.8 Critical2023-05-08

All 16 known CVE vulnerabilities affecting Aruba Access Points running InstantOS and ArubaOS 10 with full Chinese analysis, references, and POCs where available.