CVE-2025-37159

MEDIUM

AOS-CX OS - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.

Scores

CVSS v3 5.8
EPSS 0.0003
EPSS Percentile 7.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-384
Status published
Products (1)
hpe/arubaos-cx 10.10.0000 - 10.10.1170
Published Nov 18, 2025
Tracked Since Feb 18, 2026