High-Severity Flaws in HPE Aruba Networking Expose Mobility Controllers to Attack
ID: b0fd499b-1a3f-5a02-b4a2-84424a3aadfd
STIX ID: report--b0fd499b-1a3f-5a02-b4a2-84424a3aadfd
Feed Name: securityonline.info
HPE Aruba Networking published a critical advisory for AOS‑8 and AOS‑10 that fixes multiple high-severity vulnerabilities—most notably CVE‑2025‑37168, an unauthenticated arbitrary file deletion (CVSS 8.2) that can cause DoS on Mobility Conductors—and several authenticated flaws (stack overflow, command injection, file upload) that can lead to privilege escalation or remote code execution; patches are available for supported versions while EOM branches remain unpatched, with temporary mitigations recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
