CVE-2025-37156: HPE Arubaos-Cx
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.
Affected products
- HPE Arubaos-Cx: from 10.10.0000, before 10.10.1170 (fixed in 10.10.1170); from 10.13.0000, before 10.13.1101 (fixed in 10.13.1101); from 10.14.0000, before 10.14.1060 (fixed in 10.14.1060); from 10.15.0000, before 10.15.1030 (fixed in 10.15.1030); from 10.16.0000, before 10.16.1001 (fixed in 10.16.1001)
Published 2025-11-18. Last modified 2026-06-17.