vulnerability
Aruba AOS-CX: CVE-2025-37159: Authenticated Session Hijacking Allows Unauthorized Access in Network Switching Software
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:L/AC:M/Au:M/C:C/I:C/A:N) | Nov 18, 2025 | Nov 28, 2025 | Nov 28, 2025 |
Severity
6
CVSS
(AV:L/AC:M/Au:M/C:C/I:C/A:N)
Published
Nov 18, 2025
Added
Nov 28, 2025
Modified
Nov 28, 2025
Description
A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.
Solution
aruba-aos-cx-cve-2025-37159
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.