CVE-2025-37124
BaseFortify
Publication date: 2025-09-16
Last updated on: 2025-09-17
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hpe | aruba_networking_sd-wan_gateways | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-693 | The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in HPE Aruba Networking SD-WAN Gateways allows an unauthenticated remote attacker to bypass firewall protections. This means the attacker can potentially route harmful traffic through the internal network without being blocked by the firewall.
How can this vulnerability impact me? :
The impact of this vulnerability includes unauthorized access to the internal network and disruption of services. An attacker exploiting this flaw could route malicious traffic internally, potentially compromising confidentiality, integrity, and availability of network resources.