CVE-2025-37135
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-14
Last updated on: 2025-11-12
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| arubanetworks | arubaos | From 8.10.0.0 (inc) to 8.10.0.19 (exc) |
| arubanetworks | arubaos | From 8.12.0.0 (inc) to 8.12.0.6 (exc) |
| arubanetworks | arubaos | From 8.13.0.0 (inc) to 8.13.1.0 (exc) |
| arubanetworks | arubaos | From 10.4.0.0 (inc) to 10.4.1.9 (exc) |
| arubanetworks | arubaos | From 10.7.0.0 (inc) to 10.7.2.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves arbitrary file deletion in the command-line interface of an AOS-8 Controller/Mobility Conductor. An authenticated remote attacker could exploit this to delete any files on the affected system.
How can this vulnerability impact me? :
Exploitation of this vulnerability could lead to deletion of important files, potentially disrupting system operations, causing data loss, and impacting availability of the affected system.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70