A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | — | To address the vulnerabilities described above in the affected
software branches, it is recommended to upgrade HPE Networking
AOS-CX to one of the following versions (as applicable):
- AOS-CX 10.17.xxxx: AOS-CX 10.17.1001 and above
- AOS-CX 10.16.xxxx: AOS-CX 10.16.1030 and above
- AOS-CX 10.13.xxxx: AOS-CX 10.13.1161 and above
- AOS-CX 10.10.xxxx: AOS-CX 10.10.1180 and above
Software versions with resolution/fixes for the vulnerabilities
covered above can be downloaded from the HPE Networking
Support Portal at https://networkingsupport.hpe.com/home/
HPE Aruba Networking does not evaluate or patch software branches
that have reached their End of Maintenance (EoM) milestone.
For more information about HPE Aruba Networking End of Life policy
please visit:
https://www.hpe.com/psnow/doc/a00143052enw | Mar 16, 2026 | Mar 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub