A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches.
History

Tue, 18 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-359
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches.
Title Authenticated Access Control Vulnerability allows Sensitive Information Disclosure in AOS-CX REST Interface
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-03-18T19:27:35.020Z

Reserved: 2025-01-31T21:19:15.435Z

Link: CVE-2025-25042

cve-icon Vulnrichment

Updated: 2025-03-18T19:27:30.194Z

cve-icon NVD

Status : Received

Published: 2025-03-18T19:15:49.447

Modified: 2025-03-18T20:15:26.177

Link: CVE-2025-25042

cve-icon Redhat

No data.