Airwave
40 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Airwave, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Airwave CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 40 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High25
- Medium13
Latest CVEs
The 15 most recently published vulnerabilities affecting Airwave.
- CVE-2025-37163Authenticated Command Injection Vulnerability in HPE Aruba Networking Management Software (AirWave) CLI7.2
- CVE-2023-4896Authenticated Disclosure of Sensitive Information in AirWave Management Platform6.8
- CVE-2015-2202Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.7.2
- CVE-2015-2201Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.7.2
- CVE-2015-1391Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.8.8
- CVE-2015-1390Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.6.1
- CVE-2022-37918Broken Access Control for some Web-based Management URLs in AirWave Management Platform8.1
- CVE-2022-37916Broken Access Control for some Web-based Management URLs in AirWave Management Platform8.1
- CVE-2022-37917Broken Access Control for some Web-based Management URLs in AirWave Management Platform8.1
- CVE-2021-37715A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.13.0. Aruba has released upgrades for the Aruba AirWave Management Pla...4.8
- CVE-2021-29137A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this...6.1
- CVE-2021-25167A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address ...8.8
- CVE-2021-25166A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address ...8.8
- CVE-2021-25163A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address ...8.1
- CVE-2021-25165A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address ...8.1
Product grouping is registry-driven, with AI assist and human review. How it works