{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T06:56:07.487","vulnerabilities":[{"cve":{"id":"CVE-2025-37178","sourceIdentifier":"security-alert@hpe.com","published":"2026-01-13T20:16:05.983","lastModified":"2026-06-17T09:15:18.677","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process."},{"lang":"es","value":"Múltiples vulnerabilidades de lectura fuera de límites fueron identificadas en un componente del sistema responsable de manejar ciertos búferes de datos. Debido a una validación insuficiente de los valores de tamaño máximo del búfer, el proceso puede intentar leer más allá de la región de memoria prevista. Bajo condiciones específicas, esto puede resultar en una caída del proceso afectado y una potencial denegación de servicio del proceso comprometido."}],"affected":[{"source":"security-alert@hpe.com","affectedData":[{"vendor":"Hewlett Packard Enterprise (HPE)","product":"ArubaOS (AOS)","defaultStatus":"affected","versions":[{"version":"8.12.0.0","lessThanOrEqual":"8.13.1.0","versionType":"semver","status":"affected"},{"version":"8.10.0.0","lessThanOrEqual":"8.10.0.20","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-alert@hpe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-13T20:46:29.652570Z","id":"CVE-2025-37178","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*","versionStartIncluding":"8.6.0.0","versionEndExcluding":"8.10.0.21","matchCriteriaId":"28EE6221-D715-48C4-B181-BD530080E706"},{"vulnerable":true,"criteria":"cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*","versionStartIncluding":"8.11.0.0","versionEndExcluding":"8.13.1.1","matchCriteriaId":"1C7390DD-329B-44A3-9693-34211258DF37"}]}]}],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04987en_us&docLocale=en_US","source":"security-alert@hpe.com","tags":["Vendor Advisory"]}]}}]}