CVE-2025-37156
MEDIUMDescription
A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.
Is your site exposed to CVE-2025-37156?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| hpe | arubaos-cx |
| hpe | arubaos-cx |
| hpe | arubaos-cx |
| hpe | arubaos-cx |
| hpe | arubaos-cx |
References
Frequently Asked Questions
What is CVE-2025-37156? +
How severe is CVE-2025-37156? +
What products are affected by CVE-2025-37156? +
How do I check if I'm vulnerable to CVE-2025-37156? +
Related Vulnerabilities
A remote code execution issue exists in HPE OneView.
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
An authentication bypass vulnerability exists in HPE StoreOnce Software.