A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects:
- AOS-CX 10.14.xxxx : All patches
- AOS-CX 10.15.xxxx : 10.15.1000 and below
The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 | |
Metrics |
ssvc
|
Tue, 18 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability. | |
Title | Failure to Properly Enforce Port ACLs on CPU generated packets in CX 9300 Switches | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: hpe
Published: 2025-03-18T18:59:54.510Z
Updated: 2025-03-18T19:24:02.485Z
Reserved: 2025-01-31T21:19:15.435Z
Link: CVE-2025-25040

Updated: 2025-03-18T19:22:12.520Z

Status : Received
Published: 2025-03-18T19:15:49.290
Modified: 2025-03-18T20:15:26.030
Link: CVE-2025-25040

No data.