Access Control Vulnerability in HPE Network Management Services
CVE-2025-37155
7.8HIGH
What is CVE-2025-37155?
A critical access control vulnerability in the SSH restricted shell interface of HPE Network Management Services could enable authenticated read-only users to escalate their privileges, granting them unauthorized administrative access. This security issue poses a significant risk as it compromises the integrity and confidentiality of the system, allowing potential malicious activities if exploited.
Affected Version(s)
HPE Aruba Networking AOS-CX 10.16.0000 <= 10.16.1000
HPE Aruba Networking AOS-CX 10.16.0000 <= 10.16.1000
HPE Aruba Networking AOS-CX 10.15.0000 <= 10.15.1020
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Angelo Catalani
Giacomo Gloria
