7.2
CVE-2025-37173
- EPSS 0.12%
- Veröffentlicht 13.01.2026 20:04:57
- Zuletzt bearbeitet 23.01.2026 16:44:30
- Quelle security-alert@hpe.com
- CVE-Watchlists
- Unerledigt
Improper Input Handling Vulnerability in Authenticated Configuration API Endpoint (AOS-10/AOS-8 Web UI)
An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Arubaos Version >= 6.5.4.0 < 8.10.0.21
Arubanetworks ≫ Arubaos Version >= 8.11.0.0 < 8.13.1.1
Arubanetworks ≫ Arubaos Version >= 10.3.0.0 < 10.4.1.10
Arubanetworks ≫ Arubaos Version >= 10.5.0.0 < 10.7.2.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.308 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-alert@hpe.com | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.