6.5
CVE-2025-37177
- EPSS 0.12%
- Veröffentlicht 13.01.2026 20:08:06
- Zuletzt bearbeitet 23.01.2026 16:10:10
- Quelle security-alert@hpe.com
- CVE-Watchlists
- Unerledigt
Authenticated Arbitrary File Deletion Vulnerability in AOS-10 or AOS-8 Command Line Interface (CLI)
An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Arubaos Version >= 6.5.4.0 < 8.10.0.21
Arubanetworks ≫ Arubaos Version >= 8.11.0.0 < 8.13.1.1
Arubanetworks ≫ Arubaos Version >= 10.3.0.0 < 10.4.1.10
Arubanetworks ≫ Arubaos Version >= 10.5.0.0 < 10.7.2.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.307 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-alert@hpe.com | 6.5 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.