Hewlett Packard Enterprise EdgeConnect SD-WAN是美国Hewlett Packard Enterprise公司的为零信任和 SASE 提供安全的网络基础。它包括一流的 SD-WAN 和下一代防火墙,可提供无与伦比的体验质量和高级安全性。 Hewlett Packard Enterprise EdgeConnect SD-WAN ECOS存在安全漏洞,该漏洞源于具有管理员权限的认证远程威胁参与者可能访问未经授权的敏感系统文件,可能导致信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | HPE Aruba Networking EdgeConnect SD-WAN Gateway | 9.5.0.0 ~ 9.5.3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-37123 | 8.8 HIGH | Authenticated Command Injection leads to Unauthorized Actions in CLI Interface |
| CVE-2025-37124 | 8.6 HIGH | Unauthenticated Access Vulnerability allows Transit Traffic Misrouting in SD-WAN Edge Inte |
| CVE-2025-37125 | 7.5 HIGH | Broken access control vulnerability in Firewall Configuration Leads to Unauthorized Acces |
| CVE-2025-37126 | 7.2 HIGH | Authenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Gateways C |
| CVE-2025-37127 | 7.2 HIGH | Authenticated Replay Attack contains Cryptographic Vulnerability |
| CVE-2025-37128 | 6.8 MEDIUM | Authenticated Arbitrary Process Termination allows potential System Disruption in ECOS |
| CVE-2025-37129 | 6.7 MEDIUM | Authenticated Remote Code Execution allows Exploit in Scripts Feature |
| CVE-2025-37130 | 6.5 MEDIUM | Unrestricted Binary allows File Enumeration in Underlying Operating System |
No comments yet