Reflected Cross-Site Scripting Vulnerability in HPE Network Access Control Services
CVE-2025-37122
What is CVE-2025-37122?
A vulnerability exists in the web-based management interface of HPE's Network Access Control Services that allows unauthenticated attackers to perform reflected Cross-Site Scripting (XSS) attacks. If successfully exploited, attackers can execute arbitrary JavaScript code within the browser of a user interacting with the affected interface, potentially leading to unauthorized access and manipulation of user sessions. Organizations using these services should assess their exposure and implement necessary security measures to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HPE Aruba Networking ClearPass Policy Manager 6.12.0 <= 6.12.5
HPE Aruba Networking ClearPass Policy Manager 6.12.0 <= 6.12.5
HPE Aruba Networking ClearPass Policy Manager 6.11.0 <= 6.11.12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
