Impact
An attacker can trigger a buffer overflow in the command line interface of HPE AOS‑CX, which causes the system to execute arbitrary code with operating‑system privileges. The vulnerability is a classic stack-based overflow (CWE‑120) and allows a low‑privileged authenticated user to gain full control of the device, compromising confidentiality, integrity, and availability.
Affected Systems
The affected system is the Hewlett Packard Enterprise AOS‑CX networking platform. The vulnerability exists in the command line interface; specific vulnerable versions are not listed in the CVE payload, so all current deployments using the CLI should be considered potentially at risk.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is classified as high severity. The EPSS score is below 1 %, indicating a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticate with a low‑privileged account and use the CLI to trigger the overflow; once triggered, they can elevate privileges to the underlying operating system and execute arbitrary code.
OpenCVE Enrichment