CVE-2025-37139: Hewlett Packard Enterprise HPE Arubaos Aos
Medium severity, CVSS 6.0. EPSS: 0.1% chance of exploitation in the next 30 days.
A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.
Affected products
- Hewlett Packard Enterprise HPE Arubaos Aos: from 10.7.0.0, up to and including 10.7.1.1; from 10.4.0.0, up to and including 10.4.1.8; from 8.13.0.0, up to and including 8.13.0.1; from 8.12.0.0, up to and including 8.12.0.5; from 8.10.0.0, up to and including 8.10.0.18
Published 2025-10-14. Last modified 2026-10-08.