{"api_version":"v1","generated_at":"2026-10-10T09:20:00+00:00","product":{"cve_count":34,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-hewlett-packard-enterprise-hpe-arubaos-aos-60cac304a1f8","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"ArubaOS (AOS)","next_cursor":null,"observations":[{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2","affected_versions_present":true,"cve_id":"CVE-2026-23823","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23823","fixed":"To address this vulnerability, upgrade HPE Aruba Networking AOS-10 AP software to one of the following versions (as applicable): - AOS-10 AP 10.8.x.x: 10.8.0.1 and above - AOS-10 AP 10.7.x.x: 10.7.2.3 and above","last_modified":"2026-05-13T03:58:36.867Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-05-12T18:38:44.771Z"},{"affected":"8.13.0.0 \u2264 8.13.1.1; 8.12.0.0 \u2264 8.12.0.6; 8.10.0.0 \u2264 8.10.0.21","affected_versions_present":true,"cve_id":"CVE-2026-23822","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23822","fixed":"To address this vulnerability, upgrade HPE Aruba Networking AOS-8 Instant software to one of the following versions (as applicable): - AOS-8 Instant 8.13.x.x: 8.13.1.2 and above - AOS-8 Instant 8.12.x.x: 8.12.0.7 and above - AOS-8 Instant 8.10.x.x: 8.10.0.22 and above","last_modified":"2026-05-12T19:25:55.101Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-05-12T18:37:08.787Z"},{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2; 10.4.0.0 \u2264 10.4.1.10","affected_versions_present":true,"cve_id":"CVE-2026-23821","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23821","fixed":"To address this vulnerability, upgrade HPE Aruba Networking AOS-10 AP software to one of the following versions (as applicable): - AOS-10 AP 10.8.x.x: 10.8.0.1 and above - AOS-10 AP 10.7.x.x: 10.7.2.3 and above - AOS-10 AP 10.4.x.x: 10.4.1.11 and above","last_modified":"2026-05-13T03:58:38.032Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-05-12T18:35:34.806Z"},{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2; 10.4.0.0 \u2264 10.4.1.10; 8.13.0.0 \u2264 8.13.1.1; 8.12.0.0 \u2264 8.12.0.6; 8.10.0.0 \u2264 8.10.0.21","affected_versions_present":true,"cve_id":"CVE-2026-23820","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23820","fixed":"To address the vulnerabilities described above in the affected software branches, upgrade HPE Aruba Networking AOS-10 AP and AOS-8 Instant software to one of the following versions (as applicable): - AOS-10 AP 10.8.x.x: 10.8.0.1 and above - AOS-10 AP 10.7.x.x: 10.7.2.3 and above - AOS-10 AP 10.4.x.x: 10.4.1.11 and above - AOS-8 Instant 8.13.x.x: 8.13.1.2 and above - AOS-8 Instant 8.12.x.x: 8.12.0.7 and above - AOS-8 Instant 8.10.x.x: 8.10.0.22 and above","last_modified":"2026-05-13T03:58:39.169Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-05-12T18:34:34.107Z"},{"affected":"10.8.0.0; 10.7.0.0 \u2264 10.7.2.2; 10.4.0.0 \u2264 10.4.1.10; 8.13.0.0 \u2264 8.13.1.1; 8.12.0.0 \u2264 8.12.0.6; 8.10.0.0 \u2264 8.10.0.21","affected_versions_present":true,"cve_id":"CVE-2026-23819","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23819","fixed":"To address the vulnerabilities described above in the affected software branches, upgrade HPE Aruba Networking AOS-10 AP and AOS-8 Instant software to one of the following versions (as applicable): - AOS-10 AP 10.8.x.x: 10.8.0.1 and above - AOS-10 AP 10.7.x.x: 10.7.2.3 and above - AOS-10 AP 10.4.x.x: 10.4.1.11 and above - AOS-8 Instant 8.13.x.x: 8.13.1.2 and above - AOS-8 Instant 8.12.x.x: 8.12.0.7 and above - AOS-8 Instant 8.10.x.x: 8.10.0.22 and above","last_modified":"2026-05-12T19:31:00.149Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-05-12T18:31:33.726Z"},{"affected":"8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37179","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37179","fixed":"In the AOS-10.x branch, CVE-2025-37178 and CVE-2025-37179 are both resolved in versions 10.4.1.12 and 10.7.2.5 and above. For AOS-8.x systems, please refer to the Resolution section for the applicable fixed versions. RESOLUTION Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above(*) - AOS-10.4.x.x: 10.4.1.10 and above(*) - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above (*)NOTE: AOS-10.x versions 10.4.1.10 and 10.7.2.2 include fixes for every vulnerability except CVE-2025-37178 and CVE-2025-37179. For more details, please see the note in the \"Out-of-Bounds Read Vulnerabilities Leading to Process Crash (CVE-2025-37178, CVE-2025-37179)\" section of the document.","last_modified":"2026-01-13T20:32:08.785Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:08:58.718Z"},{"affected":"8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37178","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37178","fixed":"In the AOS-10.x branch, CVE-2025-37178 and CVE-2025-37179 are both resolved in versions 10.4.1.12 and 10.7.2.5 and above. For AOS-8.x systems, please refer to the Resolution section for the applicable fixed versions. RESOLUTION Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above(*) - AOS-10.4.x.x: 10.4.1.10 and above(*) - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above (*)NOTE: AOS-10.x versions 10.4.1.10 and 10.7.2.2 include fixes for every vulnerability except CVE-2025-37178 and CVE-2025-37179. For more details, please see the note in the \"Out-of-Bounds Read Vulnerabilities Leading to Process Crash (CVE-2025-37178, CVE-2025-37179)\" section of the document.","last_modified":"2026-01-13T20:46:35.369Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:08:23.659Z"},{"affected":"10.6.0.0 \u2264 10.7.2.1; 10.3.0.0 \u2264 10.4.1.9; 8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37177","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37177","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-01-13T20:54:14.563Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:08:06.545Z"},{"affected":"8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37176","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37176","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T15:04:11.064Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:07:50.236Z"},{"affected":"10.6.0.0 \u2264 10.7.2.1; 10.3.0.0 \u2264 10.4.1.9; 8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37175","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37175","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T15:04:11.385Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:07:34.158Z"},{"affected":"10.6.0.0 \u2264 10.7.2.1; 10.3.0.0 \u2264 10.4.1.9; 8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37174","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37174","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T15:04:11.669Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:05:33.134Z"},{"affected":"10.6.0.0 \u2264 10.7.2.1; 10.3.0.0 \u2264 10.4.1.9; 8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37173","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37173","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T15:04:11.948Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:04:57.366Z"},{"affected":"8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37172","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37172","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T15:04:12.244Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:04:38.071Z"},{"affected":"8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37171","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37171","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T15:04:12.546Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:04:22.468Z"},{"affected":"8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37170","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37170","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T15:04:12.831Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:04:03.744Z"},{"affected":"10.6.0.0 \u2264 10.7.2.1; 10.3.0.0 \u2264 10.4.1.9","affected_versions_present":true,"cve_id":"CVE-2025-37169","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37169","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T15:04:13.157Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:03:33.822Z"},{"affected":"8.12.0.0 \u2264 8.13.1.0; 8.10.0.0 \u2264 8.10.0.20","affected_versions_present":true,"cve_id":"CVE-2025-37168","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37168","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.2 and above - AOS-10.4.x.x: 10.4.1.10 and above - AOS-8.13.x.x: 8.13.1.1 and above - AOS-8.10.x.x: 8.10.0.21 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-01-14T18:56:26.327Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2026-01-13T20:03:08.524Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37145","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37145","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-15T13:26:22.396Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T17:02:25.602Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37144","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37144","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-15T13:33:21.809Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T17:01:45.802Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37143","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37143","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-14T18:19:14.303Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T17:00:24.490Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37142","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37142","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-14T19:27:36.196Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:59:42.542Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37141","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37141","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-14T19:26:49.673Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:59:14.551Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37140","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37140","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-14T19:26:15.112Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:58:41.022Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37139","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37139","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-14T19:25:30.743Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:58:14.200Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37138","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37138","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-14T19:24:40.242Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:57:50.910Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37137","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37137","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-14T19:23:51.609Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:57:32.140Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37136","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37136","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-14T19:22:49.575Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:56:58.248Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37135","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37135","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-10-14T19:20:58.042Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:56:37.077Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37134","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37134","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T17:47:30.962Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:56:05.389Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37133","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37133","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T17:47:31.319Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:54:36.030Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37132","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37132","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.7.x.x: 10.7.2.1 and above; - AOS-10.4.x.x: 10.4.1.9 and above; - AOS-8.13.x.x: 8.13.1.0 and above; - AOS-8.12.x.x: 8.12.0.6 and above; - AOS-8.10.x.x: 8.10.0.19 and above. Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T17:47:31.640Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:53:16.724Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37148","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37148","fixed":"Upgrade HPE Aruba Networking AOS-8 Instant APs and AOS-10 APs to one of the following software versions (as applicable) to resolve the vulnerabilities described above in the details sections: - AOS-10 AP 10.7.x.x: 10.7.2.0 and above - AOS-10 AP 10.4.x.x: 10.4.1.8 and above - AOS-8 Instant 8.13.x.x: 8.13.1.0 and above - AOS-8 Instant 8.12.x.x: 8.12.0.6 and above - AOS-8 Instant 8.10.x.x: 8.10.0.17 and above","last_modified":"2025-10-14T19:15:02.395Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:43:35.134Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37147","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37147","fixed":"Upgrade HPE Aruba Networking AOS-8 Instant APs and AOS-10 APs to one of the following software versions (as applicable) to resolve the vulnerabilities described above in the details sections: - AOS-10 AP 10.7.x.x: 10.7.2.0 and above - AOS-10 AP 10.4.x.x: 10.4.1.8 and above - AOS-8 Instant 8.13.x.x: 8.13.1.0 and above - AOS-8 Instant 8.12.x.x: 8.12.0.6 and above - AOS-8 Instant 8.10.x.x: 8.10.0.17 and above","last_modified":"2025-10-14T19:13:51.499Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:42:57.397Z"},{"affected":"ArubaOS (AOS): 10.7.0.0 \u2264 10.7.1.1, 10.4.0.0 \u2264 10.4.1.8, 8.13.0.0 \u2264 8.13.0.1, 8.12.0.0 \u2264 8.12.0.5, 8.10.0.0 \u2264 8.10.0.18","affected_versions_present":true,"cve_id":"CVE-2025-37146","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-37146","fixed":"Upgrade HPE Aruba Networking AOS-8 Instant APs and AOS-10 APs to one of the following software versions (as applicable) to resolve the vulnerabilities described above in the details sections: - AOS-10 AP 10.7.x.x: 10.7.2.0 and above - AOS-10 AP 10.4.x.x: 10.4.1.8 and above - AOS-8 Instant 8.13.x.x: 8.13.1.0 and above - AOS-8 Instant 8.12.x.x: 8.12.0.6 and above - AOS-8 Instant 8.10.x.x: 8.10.0.17 and above","last_modified":"2026-02-26T17:47:31.947Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-10-14T16:42:31.080Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"Hewlett Packard Enterprise (HPE)"}}
