Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | — | In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Aruba Networking AOS-CX software to one of the following versions (as applicable):
- AOS-CX 10.10.1181 and above
- AOS-CX 10.13.1190 and above
- AOS-CX 10.16.1060 and above
- AOS-CX 10.17.1030 and above
- AOS-CX 10.18.1002 and above
Software versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.
Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation. | Sep 2, 2026 | Sep 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub