CVE-2025-25042
Published: Mar 18, 2025
Modified: Mar 18, 2025
CVSS v3.1
4.3
Description
A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches.
| Vendor | Product | Versions |
|---|---|---|
Hewlett Packard Enterprise (HPE) | AOS-CX | affected 10.10.0000 - <= <=10.10.1140affected 10.13.0000 - <= <=10.13.1070affected 10.14.0000 - <= <=10.14.1030affected 10.15.0000 - <= <=10.15.1000 |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now