CVE-2015-2201: Arubanetworks Airwave

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.

Affected products

  • Arubanetworks Airwave: from 7.0.0, before 7.7.14.2 (fixed in 7.7.14.2)
  • HP Airwave: from 8.0.0.0, before 8.0.7 (fixed in 8.0.7)

Published 2023-09-05. Last modified 2026-06-17.