« Volver al listado

CVE-2025-37102

Estado: AplazadaAlta (7.2)—

An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points.

A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/PR:H/UI:N indica acceso remoto autenticado con privilegios elevados. Command injection permite ejecución de comandos en el SO como usuario privilegiado.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-37102",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-37102",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-08T19:42:16.230373Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-alert@hpe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "Hewlett Packard Enterprise (HPE)",
          "product": "HPE Networking Instant On",
          "versions": [
            {
              "status": "affected",
              "version": "3.2.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "3.2.0.1"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-07-08T19:15:41.753",
  "references": [
    {
      "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us&docLocale=en_US",
      "source": "security-alert@hpe.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points.  \n\nA successful exploitation could allow a remote attacker with elevated  privileges to execute arbitrary commands on the underlying operating system as a highly privileged user."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de inyección de comandos autenticados en la interfaz de línea de comandos de los puntos de acceso HPE Networking Instant On. Una explotación exitosa podría permitir que un atacante remoto con privilegios elevados ejecute comandos arbitrarios en el sistema operativo subyacente como un usuario con privilegios elevados."
    }
  ],
  "lastModified": "2026-06-17T09:15:11.517",
  "sourceIdentifier": "security-alert@hpe.com"
}