CVE-2025-37139

MEDIUM

AOS Firmware - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.

Scores

CVSS v3 6.0
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (5)
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 10.4.0.0 - 10.4.1.8
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 10.7.0.0 - 10.7.1.1
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 8.10.0.0 - 8.10.0.18
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 8.12.0.0 - 8.12.0.5
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS) 8.13.0.0 - 8.13.0.1
Published Oct 14, 2025
Tracked Since Feb 18, 2026