7.5
CVE-2025-37178
- EPSS 0.08%
- Veröffentlicht 13.01.2026 20:08:23
- Zuletzt bearbeitet 23.01.2026 16:06:12
- Quelle security-alert@hpe.com
- CVE-Watchlists
- Unerledigt
Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating System
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Arubaos Version >= 8.6.0.0 < 8.10.0.21
Arubanetworks ≫ Arubaos Version >= 8.11.0.0 < 8.13.1.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.239 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| security-alert@hpe.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.