A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Oct 2025 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.
Title Vulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable Boot
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-10-14T19:25:30.743Z

Reserved: 2025-04-16T01:28:25.368Z

Link: CVE-2025-37139

cve-icon Vulnrichment

Updated: 2025-10-14T19:25:27.394Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-14T17:15:40.697

Modified: 2025-10-14T20:15:35.597

Link: CVE-2025-37139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.