Known vulnerabilities in Aruba Networking EdgeConnect SD-WAN Gateways

Vendor: HPE
Software CPE: cpe:2.3:a:hpe:aruba_networking_edgeconnect_sd-wan_gateways:*:*:*:*:*:*:*:*
Total vulnerabilities: 9
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Aruba Networking EdgeConnect SD-WAN Gateways Aruba Networking EdgeConnect SD-WAN Gateways is affected by 9 known vulnerabilities: 1 high, 4 medium, 4 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU115745 - Exposure of sensitive information to an unauthorized actor
CVE-2025-37131
CWE-200 Low
No
No
9.4.4.2, 9.5.4.1 17.09.2025 SB2025091778
#VU115744 - Exposure of sensitive information to an unauthorized actor
CVE-2025-37130
CWE-200 Medium
No
No
9.4.4.2, 9.5.4.1 17.09.2025 SB2025091778
#VU115743 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37129
CWE-78 Low
No
No
9.4.4.2, 9.5.4.1 17.09.2025 SB2025091778
#VU115742 - Improper Access Control
CVE-2025-37128
CWE-284 Medium
No
No
9.4.4.2, 9.5.4.1 17.09.2025 SB2025091778
#VU115741 - Cryptographic Issues
CVE-2025-37127
CWE-310 Low
No
No
9.4.4.2, 9.5.4.1 17.09.2025 SB2025091778
#VU115740 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37126
CWE-78 Low
No
No
9.3.0.0 17.09.2025 SB2025091778
#VU115739 - Improper Access Control
CVE-2025-37125
CWE-284 Medium
No
No
9.4.3.5, 9.5.3.3 17.09.2025 SB2025091778
#VU115738 - Improper Access Control
CVE-2025-37124
CWE-284 High
No
No
9.2.11.3, 9.3.8.0, 9.4.3.5, 9.5.3.3 17.09.2025 SB2025091778
#VU115729 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37123
CWE-78 Medium
No
No
9.5.3.3 17.09.2025 SB2025091778