CVE-2025-37155: Authenticated Privilege Escalation Allows Unauthorized Access in Network Management Interface
A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this vulnerability could allow an attacker with read-only privileges to gain administrator access on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37155?
The severity of CVE-2025-37155 is rated as high due to the potential for read-only users to gain unauthorized administrator access.
How do I fix CVE-2025-37155?
To fix CVE-2025-37155, update your HPE ArubaOS-CX to a version beyond the vulnerable ranges mentioned in the advisory.
Who is affected by CVE-2025-37155?
CVE-2025-37155 affects users of HPE ArubaOS-CX versions between 10.10.0000 and 10.10.1170, 10.13.0000 and 10.13.1101, 10.14.0000 and 10.14.1060, 10.15.0000 and 10.15.1030, and 10.16.0000 and 10.16.1001.
What can an attacker do if they exploit CVE-2025-37155?
If exploited, CVE-2025-37155 allows attackers with read-only privileges to escalate their access and gain administrative privileges.
Is there a workaround for CVE-2025-37155?
There are no specific workarounds for CVE-2025-37155; updating to a fixed version is the recommended course of action.