CVE-2025-37148Uncontrolled Resource Consumption in Packard Enterprise Arubaos

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 79.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

CVEListV5hewlett_packard_enterprise/arubaos10.7.0.010.7.1.1+4

🔴Vulnerability Details

2
GHSA
GHSA-mmpv-fx78-c225: A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of se2025-10-14
CVEList
Kernel Panic triggered by Modified Ethernet Frames leads to Denial of Service Vulnerability2025-10-14
CVE-2025-37148 — Uncontrolled Resource Consumption | cvebase