CVE-2025-27080: Authenticated Sensitive Information Disclosure exposes Credentials in AOS-CX Command Line Interface
Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to lateral movement involving those services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27080?
CVE-2025-27080 is classified as a high severity vulnerability due to its potential to expose sensitive information and allow unauthorized access.
How do I fix CVE-2025-27080?
To remediate CVE-2025-27080, update the AOS-CX software to the latest version provided by Hewlett Packard Enterprise.
What type of attack does CVE-2025-27080 enable?
CVE-2025-27080 allows an authenticated remote attacker to exploit the command line interface of AOS-CX to gain unauthorized access to external services.
Who is affected by CVE-2025-27080?
The vulnerability affects users of Hewlett Packard Enterprise AOS-CX products who utilize the command line interface.
What potential consequences does CVE-2025-27080 present?
Exploitation of CVE-2025-27080 could lead to data exposure and unauthorized access, increasing the risk of lateral movements within the network.