vulnerability

Aruba AOS-CX: CVE-2025-37159: Authenticated Session Hijacking Allows Unauthorized Access in Network Switching Software

Severity
6
CVSS
(AV:L/AC:M/Au:M/C:C/I:C/A:N)
Published
Nov 18, 2025
Added
Nov 28, 2025
Modified
Nov 28, 2025

Description

A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.

Solution

aruba-aos-cx-cve-2025-37159
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.