{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-37100",
        "assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
        "state": "PUBLISHED",
        "assignerShortName": "hpe",
        "dateReserved": "2025-04-16T01:28:25.363Z",
        "datePublished": "2025-06-10T15:05:55.025Z",
        "dateUpdated": "2025-06-10T15:19:27.298Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "HPE Aruba Networking Private 5G Core",
                    "vendor": "Hewlett Packard Enterprise (HPE)",
                    "versions": [
                        {
                            "lessThanOrEqual": "1.25.1.0",
                            "status": "affected",
                            "version": "1.24.1.0",
                            "versionType": "semver"
                        }
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "A vulnerability in the APIs of HPE Aruba Networking Private 5G Core&nbsp;could potentially expose sensitive information to unauthorized users. <br>A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information."
                        }
                    ],
                    "value": "A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. \nA successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "NONE",
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "LOW",
                        "scope": "CHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
                "shortName": "hpe",
                "dateUpdated": "2025-06-10T15:05:55.025Z"
            },
            "references": [
                {
                    "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04883en_us&docLocale=en_US"
                }
            ],
            "source": {
                "advisory": "HPESBNW04883",
                "discovery": "INTERNAL"
            },
            "title": "Exposure of Sensitive Information to an Unauthorized User in HPE Aruba Networking Private 5G Core",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-922",
                                "lang": "en",
                                "description": "CWE-922 Insecure Storage of Sensitive Information"
                            }
                        ]
                    },
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-22",
                                "lang": "en",
                                "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-06-10T15:17:03.216946Z",
                                "id": "CVE-2025-37100",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-06-10T15:19:27.298Z"
                }
            }
        ]
    }
}