CVE-2025-37131
BaseFortify
Publication date: 2025-09-16
Last updated on: 2025-09-17
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hpe | edgeconnect | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in EdgeConnect SD-WAN ECOS allows an authenticated remote attacker with admin privileges to access sensitive system files that they are not authorized to view. Under certain conditions, this unauthorized access could lead to exposure and exfiltration of sensitive information.
How can this vulnerability impact me? :
If exploited, this vulnerability could result in unauthorized disclosure of sensitive information by allowing an attacker with admin privileges to access and potentially exfiltrate sensitive system files. This could compromise the confidentiality of your data.