vulnerability
Aruba ECOS: CVE-2025-37125: Broken access control vulnerability in Firewall Configuration Leads to Unauthorized Access to Internal Network Resources
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:C/I:N/A:N) | Sep 16, 2025 | Sep 17, 2025 | Sep 19, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Sep 16, 2025
Added
Sep 17, 2025
Modified
Sep 19, 2025
Description
A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly
Solution
aruba-ecos-cve-2025-37125
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.