CVE Vulnerabilities

CVE-2025-37156

Published: Nov 18, 2025 | Modified: Dec 04, 2025
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.

Affected Software

Name Vendor Start Version End Version
Arubaos-cx Hpe 10.10.0000 (including) 10.10.1170 (excluding)
Arubaos-cx Hpe 10.13.0000 (including) 10.13.1101 (excluding)
Arubaos-cx Hpe 10.14.0000 (including) 10.14.1060 (excluding)
Arubaos-cx Hpe 10.15.0000 (including) 10.15.1030 (excluding)
Arubaos-cx Hpe 10.16.0000 (including) 10.16.1001 (excluding)

References