{"api_version":"v1","generated_at":"2026-10-10T08:45:00+00:00","product":{"cve_count":6,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-hewlett-packard-enterprise-hpe-hpe-aruba-networking-aos-d7626d6a8a69","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"HPE Aruba Networking AOS","next_cursor":null,"observations":[{"affected":"10.7.0.0 \u2264 10.7.1.0; 10.4.0.0 \u2264 10.4.1.6; 8.12.0.0 \u2264 8.12.0.3; 8.10.0.0 \u2264 8.10.0.15","affected_versions_present":true,"cve_id":"CVE-2025-27084","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27084","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerability described in the details section: - AOS-10.7.x.x: 10.7.1.1 and above - AOS-10.4.x.x: 10.4.1.7 and above - AOS-8.12.x.x: 8.12.0.4 and above - AOS-8.10.x.x: 8.10.0.16 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-04-09T17:44:59.609Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-04-08T16:32:46.764Z"},{"affected":"10.7.0.0 \u2264 10.7.1.0; 10.4.0.0 \u2264 10.4.1.6; 8.12.0.0 \u2264 8.12.0.3; 8.10.0.0 \u2264 8.10.0.15","affected_versions_present":true,"cve_id":"CVE-2025-27085","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27085","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerability described in the details section: - AOS-10.7.x.x: 10.7.1.1 and above - AOS-10.4.x.x: 10.4.1.7 and above - AOS-8.12.x.x: 8.12.0.4 and above - AOS-8.10.x.x: 8.10.0.16 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-04-09T17:45:48.190Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-04-08T16:29:25.829Z"},{"affected":"10.7.0.0 \u2264 10.7.1.0; 10.4.0.0 \u2264 10.4.1.6; 8.12.0.0 \u2264 8.12.0.3; 8.10.0.0 \u2264 8.10.0.15","affected_versions_present":true,"cve_id":"CVE-2025-27083","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27083","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerability described in the details section: - AOS-10.7.x.x: 10.7.1.1 and above - AOS-10.4.x.x: 10.4.1.7 and above - AOS-8.12.x.x: 8.12.0.4 and above - AOS-8.10.x.x: 8.10.0.16 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2025-04-09T17:44:13.731Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-04-08T16:26:50.920Z"},{"affected":"10.7.0.0 \u2264 10.7.1.0; 10.4.0.0 \u2264 10.4.1.6; 8.12.0.0 \u2264 8.12.0.3; 8.10.0.0 \u2264 8.10.0.15","affected_versions_present":true,"cve_id":"CVE-2025-27082","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27082","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerability described in the details section: - AOS-10.7.x.x: 10.7.1.1 and above - AOS-10.4.x.x: 10.4.1.7 and above - AOS-8.12.x.x: 8.12.0.4 and above - AOS-8.10.x.x: 8.10.0.16 and above Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw","last_modified":"2026-02-26T18:28:37.938Z","patch_url":"https://csaf.arubanetworking.hpe.com/","primary_source":"","published":"2025-04-08T16:22:50.625Z"},{"affected":"10.4.0.0 \u2264 10.4.1.4; 8.12.0.0 \u2264 8.12.0.2; 8.10.0.0 \u2264 8.10.0.14","affected_versions_present":true,"cve_id":"CVE-2025-23052","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-23052","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following ArubaOS versions (as applicable) to resolve the vulnerability described in the details section: - AOS-10.7.x.x: 10.7.0.0 and above - AOS-10.4.x.x: 10.4.1.5 and above - AOS-8.12.x.x: 8.12.0.3 and above - AOS-8.10.x.x: 8.10.0.15 and above","last_modified":"2025-01-23T21:14:36.522Z","patch_url":"https://csaf.arubanetworking.hpe.com/2025/hpe_aruba_networking_-_hpesbnw04723.json","primary_source":"","published":"2025-01-14T17:38:43.844Z"},{"affected":"10.4.0.0 \u2264 10.4.1.4; 8.12.0.0 \u2264 8.12.0.2; 8.10.0.0 \u2264 8.10.0.14","affected_versions_present":true,"cve_id":"CVE-2025-23051","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-23051","fixed":"Upgrade Mobility Conductors, Controllers, and Gateways to one of the following ArubaOS versions (as applicable) to resolve the vulnerability described in the details section: - AOS-10.7.x.x: 10.7.0.0 and above - AOS-10.4.x.x: 10.4.1.5 and above - AOS-8.12.x.x: 8.12.0.3 and above - AOS-8.10.x.x: 8.10.0.15 and above","last_modified":"2025-01-23T21:18:23.255Z","patch_url":"https://csaf.arubanetworking.hpe.com/2025/hpe_aruba_networking_-_hpesbnw04723.json","primary_source":"","published":"2025-01-14T17:35:25.108Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"Hewlett Packard Enterprise (HPE)"}}
