CVE-2025-25040
CVSS 3.1 Score 3.3 of 10 (low)
Details
Summary
CVE-2025-25040 is a vulnerability affecting the port access control lists (ACLs) in the AOS-CX software on HPE Aruba Networking CX 9300 Switch Series. This issue only impacts traffic originated by the CX 9300 switch platform and allows attackers to bypass ACL rules on egress ports. Consequently, port ACLs are not effectively enforced, potentially leading to unauthorized traffic and policy violations. Notably, egress VLAN ACLs and routed VLAN ACLs remain unaffected by this vulnerability. The vulnerability affects all versions of AOS-CX 10.14 and older versions of AOS-CX 10.15, specifically 10.15.1000 and below.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.