PT-2025-47389 · Arista Networks · Aos-Cx Os

0X50D

·

Published

2025-11-18

·

Updated

2025-11-19

·

CVE-2025-37159

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions AOS-CX OS (affected versions not specified)
Description A flaw exists in the web management interface of the AOS-CX OS user authentication service. An authenticated remote attacker may be able to hijack an active user session. Successful exploitation could allow an attacker to maintain unauthorized access to the session, potentially enabling them to view or modify sensitive configuration data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2025-37159

Affected Products

Aos-Cx Os