Cyber Resilience

CVE-2025-37156

Hpe Arubaos-Cx 10.10.0000 – 10.10.1170

Published
18 November 2025
Modified
04 December 2025
Patch / advisory
CVSS Score v3.1 6.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
EPSS Score 0.0029 22th percentile
Risk Priority 44 floored blend · peak EPSS

Summary

CVE-2025-37156 is a medium-severity an unspecified weakness vulnerability in Hpe Arubaos-Cx. Its CVSS base score is 6.8 (Medium).

Operationally, ranked at the 22th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-37158Same product: Hpe Arubaos-Cx
CVE-2025-37159Same product: Hpe Arubaos-Cx
CVE-2025-37160Same product: Hpe Arubaos-Cx
CVE-2026-23817Same product: Hpe Arubaos-Cx
CVE-2025-37157Same product: Hpe Arubaos-Cx
CVE-2025-37155Same product: Hpe Arubaos-Cx
CVE-2023-1168Same product: Hpe Arubaos-Cx
CVE-2023-3718Same product: Hpe Arubaos-Cx
CVE-2026-23815Same product: Hpe Arubaos-Cx
CVE-2026-63454Same product: Hpe Arubaos-Cx

Affected Assets

hpe
arubaos-cx
10.10.0000 — 10.10.1170 · 10.13.0000 — 10.13.1101 · 10.14.0000 — 10.14.1060

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References