Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 20 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hpe
Hpe arubaos |
|
| Vendors & Products |
Hpe
Hpe arubaos |
Tue, 14 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| Metrics |
ssvc
|
Tue, 14 Oct 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or custom firmware on affected Access Points. | |
| Title | Secure Boot Bypass allows for Compromise of Hardware Root of Trust | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2025-10-14T19:13:51.499Z
Reserved: 2025-04-16T01:28:25.369Z
Link: CVE-2025-37147
Updated: 2025-10-14T19:13:47.274Z
Status : Deferred
Published: 2025-10-14T17:15:41.760
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-37147
No data.
OpenCVE Enrichment
Updated: 2025-10-20T15:49:28Z