CVE-2025-37160
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-18
Last updated on: 2025-12-04
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hpe | arubaos-cx | From 10.10.0000 (inc) to 10.10.1170 (exc) |
| hpe | arubaos-cx | From 10.13.0000 (inc) to 10.13.1101 (exc) |
| hpe | arubaos-cx | From 10.14.0000 (inc) to 10.14.1060 (exc) |
| hpe | arubaos-cx | From 10.15.0000 (inc) to 10.15.1030 (exc) |
| hpe | arubaos-cx | From 10.16.0000 (inc) to 10.16.1001 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |