CVE-2016-2031: Arubanetworks Airwave
Critical severity, CVSS 9.8. EPSS: 5.1% chance of exploitation in the next 30 days.
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary code.
Affected products
- Arubanetworks Airwave: before 8.2.0.0 (fixed in 8.2.0.0)
- Arubanetworks Aruba Instant: before 4.1.3.0 (fixed in 4.1.3.0); version 4.2.3.1 only
- Arubanetworks Arubaos: any version
- Siemens Scalance w1750d Firmware: any version
Published 2020-01-31. Last modified 2026-06-17.