CVE-2025-37131

MEDIUM

EdgeConnect SD-WAN ECOS - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sensitive information.

Scores

CVSS v3 4.9
EPSS 0.0030
EPSS Percentile 21.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking EdgeConnect SD-WAN Gateway 9.4.0.0 - 9.4.3.7
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking EdgeConnect SD-WAN Gateway 9.5.0.0 - 9.5.3.6
Published Sep 16, 2025
Tracked Since Feb 18, 2026