A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-250 | |
| Metrics |
ssvc
|
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arubanetworks
Arubanetworks edgeconnect Enterprise Hp Hp arubaos |
|
| Vendors & Products |
Arubanetworks
Arubanetworks edgeconnect Enterprise Hp Hp arubaos |
Tue, 16 Sep 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state. | |
| Title | Authenticated Arbitrary Process Termination allows potential System Disruption in ECOS | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published: 2025-09-16T22:22:57.383Z
Updated: 2025-09-17T14:00:38.971Z
Reserved: 2025-04-16T01:28:25.367Z
Link: CVE-2025-37128
Updated: 2025-09-17T14:00:32.964Z
Status : Awaiting Analysis
Published: 2025-09-16T23:15:32.640
Modified: 2025-09-17T14:18:55.093
Link: CVE-2025-37128
No data.