CVE-2025-25040

CVSS 3.1 Score 3.3 of 10 (low)

Details

Published Mar 18, 2025
CWE ID 863

Summary

CVE-2025-25040 is a vulnerability affecting the port access control lists (ACLs) in the AOS-CX software on HPE Aruba Networking CX 9300 Switch Series. This issue only impacts traffic originated by the CX 9300 switch platform and allows attackers to bypass ACL rules on egress ports. Consequently, port ACLs are not effectively enforced, potentially leading to unauthorized traffic and policy violations. Notably, egress VLAN ACLs and routed VLAN ACLs remain unaffected by this vulnerability. The vulnerability affects all versions of AOS-CX 10.14 and older versions of AOS-CX 10.15, specifically 10.15.1000 and below.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share