Description
A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6701 | A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches. |
References
History
Tue, 18 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-359 | |
| Metrics |
ssvc
|
Tue, 18 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches. | |
| Title | Authenticated Access Control Vulnerability allows Sensitive Information Disclosure in AOS-CX REST Interface | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2025-03-18T19:27:35.020Z
Reserved: 2025-01-31T21:19:15.435Z
Link: CVE-2025-25042
Updated: 2025-03-18T19:27:30.194Z
Status : Deferred
Published: 2025-03-18T19:15:49.447
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-25042
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD