CVE 5.3 MEDIUM

Authenticated Broken Access Control (BAC) in REST API Configuration Service_CVE-2025-37160

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.

Basic Information

ID CVE-2025-37160
Source hpe
Published Nov 18, 2025 at 18:54
Modified Nov 18, 2025 at 20:56

Affected Product

Vendor Hewlett Packard Enterprise (HPE)
Product HPE Aruba Networking AOS-CX
Version 10.16.0000
Affected Versions Hewlett Packard Enterprise (HPE) HPE Aruba Networking AOS-CX 10.16.0000
Hewlett Packard Enterprise (HPE) HPE Aruba Networking AOS-CX 10.15.0000
Hewlett Packard Enterprise (HPE) HPE Aruba Networking AOS-CX 10.14.0000
Hewlett Packard Enterprise (HPE) HPE Aruba Networking AOS-CX 10.13.0000
Hewlett Packard Enterprise (HPE) HPE Aruba Networking AOS-CX 10.10.0000

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.