CVE-2025-37125
7.5Hewlett Packard Enterprise (HPE) · HPE Aruba Networking EdgeConnect SD-WAN Gateway
A broken access control vulnerability in HPE Aruba Networking EdgeConnect OS allows unauthenticated attackers to bypass firewall protections and potentially handle network traffic improperly.
Executive summary
A critical broken access control vulnerability in HPE Aruba Networking EdgeConnect OS exposes network gateways to unauthorized traffic handling and potential security bypasses.
Vulnerability
The flaw is a broken access control issue within the EdgeConnect OS (ECOS), which allows unauthenticated remote attackers to circumvent firewall rules.
Business impact
The ability to bypass firewall protections represents a significant risk to network integrity and confidentiality. By manipulating traffic handling, unauthorized parties could potentially gain access to internal segments or intercept sensitive communications, justifying the High severity CVSS score of 7.5.
Remediation
Immediate Action: Administrators must review the official HPE security advisory and apply the provided vendor updates as soon as they become available for the affected gateway firmware.
Proactive Monitoring: Security teams should monitor network access logs and firewall traffic patterns for anomalous behavior or unexpected connection attempts that deviate from established baseline traffic.
Compensating Controls: While a patch is pending, restrict management interface access to trusted internal networks only and utilize Web Application Firewalls or intrusion detection systems to filter potentially malicious traffic.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for unauthorized traffic manipulation and the unauthenticated nature of this vulnerability, organizations should treat this as a priority. Ensure that all affected EdgeConnect gateways are identified and scheduled for immediate firmware updates to prevent potential exploitation.
More Hewlett Packard Enterprise (HPE) CVEs
Sources
Originally found and disclosed by Unknown contributor, per the CVE Program record.