CVE-2025-37128

MEDIUM

HPE Aruba Networking EdgeConnect - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.

Scores

CVSS v3 6.8
EPSS 0.0009
EPSS Percentile 25.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-250
Status published
Products (2)
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking EdgeConnect SD-WAN Gateway 9.4.0.0 - 9.4.3.7
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking EdgeConnect SD-WAN Gateway 9.5.0.0 - 9.5.3.6
Published Sep 16, 2025
Tracked Since Feb 18, 2026