Reflected Cross-Site Scripting Vulnerability in HPE Network Access Control Services
CVE-2025-37122

6.1MEDIUM

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
17 September 2025

What is CVE-2025-37122?

A vulnerability exists in the web-based management interface of HPE's Network Access Control Services that allows unauthenticated attackers to perform reflected Cross-Site Scripting (XSS) attacks. If successfully exploited, attackers can execute arbitrary JavaScript code within the browser of a user interacting with the affected interface, potentially leading to unauthorized access and manipulation of user sessions. Organizations using these services should assess their exposure and implement necessary security measures to mitigate this risk.

Affected Version(s)

HPE Aruba Networking ClearPass Policy Manager 6.12.0 <= 6.12.5

HPE Aruba Networking ClearPass Policy Manager 6.12.0 <= 6.12.5

HPE Aruba Networking ClearPass Policy Manager 6.11.0 <= 6.11.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ricky8368
.
CVE-2025-37122 : Reflected Cross-Site Scripting Vulnerability in HPE Network Access Control Services