CVE-2025-37155: HPE Arubaos-Cx

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this vulnerability could allow an attacker with read-only privileges to gain administrator access on the affected system.

Affected products

  • HPE Arubaos-Cx: from 10.10.0000, before 10.10.1170 (fixed in 10.10.1170); from 10.13.0000, before 10.13.1101 (fixed in 10.13.1101); from 10.14.0000, before 10.14.1060 (fixed in 10.14.1060); from 10.15.0000, before 10.15.1030 (fixed in 10.15.1030); from 10.16.0000, before 10.16.1001 (fixed in 10.16.1001)

Published 2025-11-18. Last modified 2026-06-17.