CVE-2025-37127
BaseFortify
Publication date: 2025-09-16
Last updated on: 2025-09-17
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hpe | aruba_networking_edgeconnect_sd-wan_gateways | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-327 | The product uses a broken or risky cryptographic algorithm or protocol. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the cryptographic logic of HPE Aruba Networking EdgeConnect SD-WAN Gateways. It allows an authenticated remote attacker to gain shell access, which means the attacker can execute arbitrary commands on the underlying operating system of the affected device.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker to gain unauthorized access and control over the affected systems by executing arbitrary commands. This could lead to compromise of system integrity, confidentiality, and availability.