{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T12:47:00.624","vulnerabilities":[{"cve":{"id":"CVE-2025-37155","sourceIdentifier":"security-alert@hpe.com","published":"2025-11-18T19:15:47.170","lastModified":"2026-06-17T09:15:16.323","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this vulnerability could allow an attacker with read-only privileges to gain administrator access on the affected system."}],"affected":[{"source":"security-alert@hpe.com","affectedData":[{"vendor":"Hewlett Packard Enterprise (HPE)","product":"HPE Aruba Networking AOS-CX","defaultStatus":"affected","versions":[{"version":"10.16.0000","lessThanOrEqual":"10.16.1000","versionType":"semver","status":"affected"},{"version":"10.15.0000","lessThanOrEqual":"10.15.1020","versionType":"semver","status":"affected"},{"version":"10.14.0000","lessThanOrEqual":"10.14.1050","versionType":"semver","status":"affected"},{"version":"10.13.0000","lessThanOrEqual":"10.13.1090","versionType":"semver","status":"affected"},{"version":"10.10.0000","lessThanOrEqual":"10.10.1160","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-alert@hpe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-11-19T04:55:36.998458Z","id":"CVE-2025-37155","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*","versionStartIncluding":"10.10.0000","versionEndExcluding":"10.10.1170","matchCriteriaId":"3FEB3830-A052-4585-BF45-9E221FA06D43"},{"vulnerable":true,"criteria":"cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*","versionStartIncluding":"10.13.0000","versionEndExcluding":"10.13.1101","matchCriteriaId":"0490B2CA-4273-426E-8776-814D242834B0"},{"vulnerable":true,"criteria":"cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*","versionStartIncluding":"10.14.0000","versionEndExcluding":"10.14.1060","matchCriteriaId":"21AC81E3-A4C8-4120-AEEA-46123B84A250"},{"vulnerable":true,"criteria":"cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*","versionStartIncluding":"10.15.0000","versionEndExcluding":"10.15.1030","matchCriteriaId":"FB5ADE5E-72CB-41E0-B7A0-08BEBB94ED8E"},{"vulnerable":true,"criteria":"cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*","versionStartIncluding":"10.16.0000","versionEndExcluding":"10.16.1001","matchCriteriaId":"5CF58D01-F13F-4DAF-B6A1-D91AEC7F19B3"}]}]}],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04888en_us&docLocale=en_US","source":"security-alert@hpe.com","tags":["Vendor Advisory"]}]}}]}