Denial of Service Vulnerability in AOS-8 Instant and AOS 10 by HPE
CVE-2025-37148
6.5MEDIUM
What is CVE-2025-37148?
A critical vulnerability exists in the parsing of Ethernet frames within AOS-8 Instant and AOS 10 products from HPE. This flaw may allow an unauthenticated remote attacker to execute a denial of service attack, potentially disrupting network services and necessitating manual intervention to restore system functionality. Organizations using these products should implement patching and protective measures to safeguard against exploitation.
Affected Version(s)
ArubaOS (AOS) 10.7.0.0 <= 10.7.1.1
ArubaOS (AOS) 10.7.0.0 <= 10.7.1.1
ArubaOS (AOS) 10.4.0.0 <= 10.4.1.8