CVE-2025-37168

8.2

Hewlett Packard Enterprise (HPE) · ArubaOS (AOS)

An arbitrary file deletion vulnerability exists in HPE ArubaOS mobility conductors, allowing unauthenticated remote attackers to delete system files and potentially cause a denial of service.

Executive summary

A critical arbitrary file deletion vulnerability in HPE ArubaOS mobility conductors poses a significant risk of service disruption and system instability from unauthenticated remote attackers.

Vulnerability

The vulnerability exists within a system function of the mobility conductor, which fails to properly validate inputs, allowing an unauthenticated remote actor to delete arbitrary files on the underlying filesystem.

Business impact

The ability for an unauthenticated attacker to delete arbitrary files can lead to critical system failure, configuration loss, or sustained denial of service conditions. With a CVSS score of 8.2, this vulnerability is classified as High, reflecting the potential for significant operational impact on network infrastructure managed by these mobility conductors.

Remediation

Immediate Action: Review the official HPE security advisory and apply the recommended firmware updates or patches as soon as they are released by the vendor.

Proactive Monitoring: Monitor system logs for unusual file access patterns, unexpected process terminations, or service restarts that may indicate an exploitation attempt.

Compensating Controls: Restrict network access to the mobility conductor management interface to trusted administrative subnets only, effectively reducing the attack surface for remote unauthenticated actors.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the severity of this vulnerability and the potential for remote disruption of network management, administrators must prioritize the identification of all affected mobility conductors in their environment. Apply vendor-supplied patches immediately upon availability to mitigate the risk of unauthorized file deletion and potential denial of service.

More Hewlett Packard Enterprise (HPE) CVEs

Sources

Originally found and disclosed by n3k, per the CVE Program record.