Aller au contenu

Fiche vulnérabilité

CVE-2025-37159 : faille élevée hpe arubaos-cx (CVSS 7.3)

Description

A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.

En bref

Sévérité
Élevée (CVSS 7.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
18 nov. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • hpe arubaos-cx

Références

Rechercher une autre vulnérabilité dans la base CVE