A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects:

- AOS-CX 10.14.xxxx : All patches
- AOS-CX 10.15.xxxx : 10.15.1000 and below
The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability.

Project Subscriptions

Vendors Products
Aruba Cx 9300 32d \(r8z96a\) Subscribe
Aruba Cx 9300 32d \(r9a29a\) Subscribe
Aruba Cx 9300 32d \(r9a30a\) Subscribe
Aruba Cx 9300 \(r8z97a\) Subscribe
Aruba Cx 9300 \(r8z98a\) Subscribe
Aruba Cx 9300 \(r8z99a\) Subscribe
Aruba Cx 9300 \(r9a00a\) Subscribe
Aruba Cx 9300s 32p \(s0f81a\) Subscribe
Aruba Cx 9300s 32p \(s0f82a\) Subscribe
Aruba Cx 9300s 32p \(s0f83a\) Subscribe
Aruba Cx 9300s 32p \(s0f84a\) Subscribe
Aruba Cx 9300s 32p \(s0f87a\) Subscribe
Aruba Cx 9300s 32p \(s0f88a\) Subscribe
Arubaos-cx Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6702 A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 22 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Hpe
Hpe aruba Cx 9300 32d \(r8z96a\)
Hpe aruba Cx 9300 32d \(r9a29a\)
Hpe aruba Cx 9300 32d \(r9a30a\)
Hpe aruba Cx 9300 \(r8z97a\)
Hpe aruba Cx 9300 \(r8z98a\)
Hpe aruba Cx 9300 \(r8z99a\)
Hpe aruba Cx 9300 \(r9a00a\)
Hpe aruba Cx 9300s 32p \(s0f81a\)
Hpe aruba Cx 9300s 32p \(s0f82a\)
Hpe aruba Cx 9300s 32p \(s0f83a\)
Hpe aruba Cx 9300s 32p \(s0f84a\)
Hpe aruba Cx 9300s 32p \(s0f87a\)
Hpe aruba Cx 9300s 32p \(s0f88a\)
Hpe arubaos-cx
CPEs cpe:2.3:h:hpe:aruba_cx_9300_32d_\(r8z96a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_32d_\(r9a29a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_32d_\(r9a30a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_\(r8z97a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_\(r8z98a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_\(r8z99a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_\(r9a00a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f81a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f82a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f83a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f84a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f87a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f88a\):-:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
Vendors & Products Hpe
Hpe aruba Cx 9300 32d \(r8z96a\)
Hpe aruba Cx 9300 32d \(r9a29a\)
Hpe aruba Cx 9300 32d \(r9a30a\)
Hpe aruba Cx 9300 \(r8z97a\)
Hpe aruba Cx 9300 \(r8z98a\)
Hpe aruba Cx 9300 \(r8z99a\)
Hpe aruba Cx 9300 \(r9a00a\)
Hpe aruba Cx 9300s 32p \(s0f81a\)
Hpe aruba Cx 9300s 32p \(s0f82a\)
Hpe aruba Cx 9300s 32p \(s0f83a\)
Hpe aruba Cx 9300s 32p \(s0f84a\)
Hpe aruba Cx 9300s 32p \(s0f87a\)
Hpe aruba Cx 9300s 32p \(s0f88a\)
Hpe arubaos-cx

Tue, 18 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability.
Title Failure to Properly Enforce Port ACLs on CPU generated packets in CX 9300 Switches
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-03-18T19:24:02.485Z

Reserved: 2025-01-31T21:19:15.435Z

Link: CVE-2025-25040

cve-icon Vulnrichment

Updated: 2025-03-18T19:22:12.520Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-18T19:15:49.290

Modified: 2026-09-22T19:57:07.170

Link: CVE-2025-25040

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses