CVE-2025-37156: ArubaOS-CX Platform-Level Denial-of-Service Vulnerability
Published Nov 18, 2025
·Updated
A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.
Affected Software
6 affected components
Aruba ArubaOS-CX
HPE Arubaos-cx>=10.10.0000<10.10.1170
HPE Arubaos-cx>=10.13.0000<10.13.1101
HPE Arubaos-cx>=10.14.0000<10.14.1060
HPE Arubaos-cx>=10.15.0000<10.15.1030
HPE Arubaos-cx>=10.16.0000<10.16.1001
Event History
Nov 18, 2025
CVE Published
via MITRE·06:46 PM
Data Sourced
via MITRE·06:46 PM
DescriptionSeverity
Data Sourced
via NVD·07:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-37156?
CVE-2025-37156 is classified as a high severity denial-of-service (DoS) vulnerability.
2
Who is affected by CVE-2025-37156?
CVE-2025-37156 affects users of ArubaOS-CX software with administrative access.
3
What can an attacker do with CVE-2025-37156?
An attacker can execute specific code that causes the switch to become non-bootable and non-functional.
4
How do I fix CVE-2025-37156?
To fix CVE-2025-37156, apply the latest security patches provided by Aruba for ArubaOS-CX.
5
What type of vulnerability is CVE-2025-37156?
CVE-2025-37156 is a platform-level denial-of-service vulnerability that affects switch functionality.