CVE-2025-37159
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-18
Last updated on: 2025-12-04
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hpe | arubaos-cx | From 10.10.0000 (inc) to 10.10.1170 (exc) |
| hpe | arubaos-cx | From 10.13.0000 (inc) to 10.13.1101 (exc) |
| hpe | arubaos-cx | From 10.14.0000 (inc) to 10.14.1060 (exc) |
| hpe | arubaos-cx | From 10.15.0000 (inc) to 10.15.1030 (exc) |
| hpe | arubaos-cx | From 10.16.0000 (inc) to 10.16.1001 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-384 | Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions. |