vulnerability

Aruba ECOS: CVE-2025-37125: Broken access control vulnerability in Firewall Configuration Leads to Unauthorized Access to Internal Network Resources

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Sep 16, 2025
Added
Sep 17, 2025
Modified
Sep 19, 2025

Description

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly

Solution

aruba-ecos-cve-2025-37125
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.