Medium severity5.3NVD Advisory· Published Nov 18, 2025· Updated Jun 17, 2026
CVE-2025-37160
CVE-2025-37160
Description
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.
Affected products
3- Hewlett Packard Enterprise (HPE)/HPE Aruba Networking AOS-CXv5Range: 10.16.0000
Patches
Vulnerability mechanics
References
1- support.hpe.com/hpesc/public/docDisplaynvdVendor Advisory
News mentions
0No linked articles in our index yet.