CVE-2025-37160

MEDIUM

ArubaOS-CX 10.10.0000-10.10.1169 - Authenticated Sensitive Information Exposure via Web Management Interface

Title source: llm
STIX 2.1

Description

A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 15.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
hpe/arubaos-cx 10.10.0000 - 10.10.1170
Published Nov 18, 2025
Tracked Since Feb 18, 2026