CVE-2025-37155

7.8

Hewlett Packard Enterprise · Aruba Networking AOS-CX

An improper access control vulnerability in the SSH restricted shell of HPE Aruba Networking AOS-CX allows authenticated read-only users to elevate their privileges to administrator.

Executive summary

A critical privilege escalation vulnerability in HPE Aruba Networking AOS-CX allows authenticated read-only users to gain administrative control over the system.

Vulnerability

This flaw exists within the SSH restricted shell interface, where insufficient validation of user capabilities allows a low-privileged, authenticated read-only user to bypass restrictions and achieve full administrative access.

Business impact

The ability for a read-only user to elevate privileges to administrator represents a complete compromise of the affected network device. Given the CVSS score of 7.8, this high-severity vulnerability could lead to unauthorized network configuration changes, data interception, and total loss of device integrity, potentially impacting overall network availability and security posture.

Remediation

Immediate Action: Review the official HPE security advisory and apply the vendor-provided firmware updates or configuration patches as soon as they are released for your specific version.

Proactive Monitoring: Audit SSH access logs for anomalous session activity or unauthorized command execution attempts originating from accounts typically restricted to read-only access.

Compensating Controls: Restrict SSH access to management interfaces to trusted administrative subnets and enforce the principle of least privilege by auditing and limiting the number of active user accounts on network hardware.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing the affected HPE Aruba Networking AOS-CX versions should prioritize identifying all devices currently running these firmware releases. Given the potential for full administrative takeover, apply the recommended vendor updates immediately upon availability to close the privilege escalation vector.

More Hewlett Packard Enterprise CVEs

Sources

Originally found and disclosed by Angelo Catalani, Giacomo Gloria, per the CVE Program record.