Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.
History

Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 16:45:00 +0000

Type Values Removed Values Added
Description Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.
Title Arbitrary File Download Vulnerabilities in Web-Based Management Interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-04-09T17:45:48.190Z

Reserved: 2025-02-18T14:05:41.921Z

Link: CVE-2025-27085

cve-icon Vulnrichment

Updated: 2025-04-09T17:45:43.763Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T17:15:36.887

Modified: 2025-04-09T18:15:44.980

Link: CVE-2025-27085

cve-icon Redhat

No data.