CVE-2025-37184: Unauthenticated Bypass Allows Multi-Factor Authentication Circumvention
A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity of secured access to the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37184?
CVE-2025-37184 has a high severity due to its potential to allow unauthorized access to admin privileges.
How do I fix CVE-2025-37184?
To fix CVE-2025-37184, update your Arubanetworks Edgeconnect SD-WAN Orchestrator to version 9.6.1 or later.
Who is affected by CVE-2025-37184?
CVE-2025-37184 affects versions 9.0 to 9.6.0 of Arubanetworks Edgeconnect SD-WAN Orchestrator.
What type of attack does CVE-2025-37184 enable?
CVE-2025-37184 enables unauthenticated remote attackers to bypass multi-factor authentication.
What could happen if CVE-2025-37184 is exploited?
If exploited, CVE-2025-37184 could allow attackers to create an admin user account, compromising the system.