Unrated severityNVD Advisory· Published Nov 18, 2025· Updated Nov 18, 2025
Authenticated Broken Access Control (BAC) in REST API Configuration Service
CVE-2025-37160
Description
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.
Affected products
1- Hewlett Packard Enterprise (HPE)/HPE Aruba Networking AOS-CXv5Range: 10.16.0000
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.