Description
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authenticated path traversal flaw in HPE AOS‑CX that lets an attacker copy arbitrary files to a directory that the operating system’s command‑line interface can read. By controlling the contents and destination of the copied file, the attacker can later execute code on the host, thus gaining remote execution privileges.

Affected Systems

Only Hewlett Packard Enterprise’s AOS‑CX platform is affected. No specific affected versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 7.2 indicates a high‑severity vulnerability, while the EPSS score of less than 1 % suggests that exploitation attempts are presently unlikely. The flaw requires authenticated access to the operating system’s CLI, so a compromised or privileged account would be needed; an attacker would issue a crafted command that abuses the path traversal to place a malicious file in a publicly accessible directory and then trigger its execution. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 05:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE AOS‑CX patch or firmware update referenced in the support article to eliminate the path traversal flaw
  • Limit command‑line interface access to trusted administrators and enforce multi‑factor authentication to reduce the attack surface, ensuring input is validated to prevent path traversal (CWE‑22)
  • Configure the system to block or monitor write operations to publicly readable directories and audit file creation events

Generated by OpenCVE AI on August 4, 2026 at 05:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hpe
Hpe aos-cx
Vendors & Products Hpe
Hpe aos-cx

Tue, 21 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
Title Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-07-24T03:55:52.403Z

Reserved: 2026-07-16T19:47:44.513Z

Link: CVE-2026-63454

cve-icon Vulnrichment

Updated: 2026-07-22T19:05:21.926Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')