MEDIUM
Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)
Published Oct 14, 2025
6.5
MEDIUMCVSS 3.1
EPSS 0.36%
Description
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.
Affected products
-
- Version 10.4.0.0StatusaffectedConstraints<=10.4.1.8
- Version 10.7.0.0StatusaffectedConstraints<=10.7.1.1
- Version 8.10.0.0StatusaffectedConstraints<=8.10.0.18
- Version 8.12.0.0StatusaffectedConstraints<=8.12.0.5
- Version 8.13.0.0StatusaffectedConstraints<=8.13.0.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | ArubaOS (AOS) | affected |
|
OR
- ≥ 8.10.0.0 · < 8.10.0.19
- ≥ 8.12.0.0 · < 8.12.0.6
- ≥ 8.13.0.0 · < 8.13.1.0
- ≥ 10.4.0.0 · < 10.4.1.9
- ≥ 10.7.0.0 · < 10.7.2.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-34439 Advisory
- https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04957en_us&docLocale=en_US Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-34439 | Advisory | |
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04957en_us&docLocale=en_US | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hpe
Published Oct 14, 2025
Updated Oct 14, 2025
Reserved Apr 16, 2025
Link CVE-2025-37136
CISA Vulnrichment
Updated Oct 14, 2025
ENISA EUVD
EUVD-2025-34439 Assigner hpe
Published Oct 14, 2025
Updated Oct 14, 2025
Exploited since n/a
Link EUVD-2025-34439