Impact
The vulnerability is a buffer overflow in a daemon of HPE AOS-CX that allows an unauthenticated attacker to send malformed packets. The improper parsing of these packets can overwrite memory and give the attacker the ability to execute arbitrary code with elevated privileges on the affected system. If successfully exploited, the attacker gains full control over the host, with potential to exfiltrate data, tamper with configuration, or deploy additional malware.
Affected Systems
The affected product is Hewlett Packard Enterprise AOS-CX. No specific version information is supplied, so all releases that incorporate the vulnerable daemon are potentially impacted. Users should verify if their deployment includes the affected code path and review the HPE support reference for patch availability.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of <1% indicates a low probability of current exploitation. The vulnerability has not been listed in the CISA KEV catalog, but the ability to execute remote code without authentication means the attack vector is inferred to be network-based, with an attacker able to trigger the defect by sending specially crafted packets to the vulnerable service. The impact is system-wide control, and there is no indication that mitigation requires special privileges beyond the normal vendor patch process.
OpenCVE Enrichment