THREAT OPS › Threat News › [NVD] CVE-2025-25040 (LOW 3.3) — A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects:
- AOS-CX 10.14.xxxx : All patches
- AOS-CX 10.15.xxxx : 10.15.1000 and below
The vulnerability is specific
[NVD] CVE-2025-25040 (LOW 3.3) — A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is specific
CVE-2025-25040 CVSS: 3.3 LOW Published: 2025-03-18T19:15:49.290
A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects:
- AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is specific to traffic originated by the CX 9300 switch platform a
Indicators of compromise
- CVE-2025-25040cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-25040