CVE-2025-23054

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 28, 2025

Summary

CVE-2025-23054 is a vulnerability affecting the web-based management interface of HPE Aruba Networking Fabric Composer. This issue enables authenticated low privilege operator users to execute functions beyond their authorized access level. An attacker who successfully exploits this vulnerability can manipulate user-generated files, potentially resulting in unauthorized modifications to critical system configurations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share