Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos 8 | — | With the exception of CVE-2025-37178 and CVE-2025-37179, the remaining vulnerabilities are resolved by upgrading Mobility Conductors, Controllers, and Gateways to one of the AOS-8 or AOS-10 versions listed below (as applicable). This upgrade remediates the vulnerabilities described in the Details section.
AOS-10.7.x.x: 10.7.2.2 and above
AOS-10.4.x.x: 10.4.1.10 and above
AOS-8.13.x.x: 8.13.1.1 and above
AOS-8.10.x.x: 8.10.0.21 and above
Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE .
HPE Aruba Networking does not evaluate or patch AOS-10 GW and AOS-8 Controller/Mobility Conductor software branches that have reached their End of Maintenance (EoM) milestone.
For more information about HPE Aruba Networking's End of Life policy visit: https://www.hpe.com/psnow/doc/a00143052enw .
| Jan 14, 2026 | Jan 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub