6.5
CVE-2025-37137
- EPSS 0.08%
- Veröffentlicht 14.10.2025 16:57:32
- Zuletzt bearbeitet 12.11.2025 21:06:42
- Quelle security-alert@hpe.com
- CVE-Watchlists
- Unerledigt
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Arubaos Version >= 8.10.0.0 < 8.10.0.19
Arubanetworks ≫ Arubaos Version >= 8.12.0.0 < 8.12.0.6
Arubanetworks ≫ Arubaos Version >= 8.13.0.0 < 8.13.1.0
Arubanetworks ≫ Arubaos Version >= 10.4.0.0 < 10.4.1.9
Arubanetworks ≫ Arubaos Version >= 10.7.0.0 < 10.7.2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.248 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-alert@hpe.com | 6.5 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.