CVE-2025-37178 is an out-of-bounds read vulnerability affecting ArubaOS, where insufficient buffer size validation can lead to attempts to read beyond allocated memory. This flaw carries a CVSS score of 7.5 (High), indicating a network-exploitable vulnerability that can result in a denial-of-service for the affected process. While there is no known active exploitation or public exploit code available, the vulnerability has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.6.0.0, < 8.10.0.21CPE matchmatch criteria | cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* | ||
>= 8.11.0.0, < 8.13.1.1CPE matchmatch criteria | cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.