CVE-2025-37100

A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information.
Configurations

No configuration.

History

12 Jun 2025, 16:06

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en las API de HPE Aruba Networking Private 5G Core podría exponer información confidencial a usuarios no autorizados. Una explotación exitosa podría permitir a un atacante navegar iterativamente por el sistema de archivos y, en última instancia, descargar archivos protegidos del sistema que contienen información confidencial.

10 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-922
CWE-22

10 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 15:15

Updated : 2025-06-12 16:06


NVD link : CVE-2025-37100

Mitre link : CVE-2025-37100

CVE.ORG link : CVE-2025-37100


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-922

Insecure Storage of Sensitive Information