Impact
The vulnerability is a buffer overflow in the authentication module of AOS‑CX that mishandles malformed or truncated input. An attacker who can provide crafted input from an authenticated session, potentially originating from a compromised authentication server, could trigger a denial of service or execute code with elevated privileges on the target system.
Affected Systems
Hewlett Packard Enterprise AOS‑CX is the affected product. Specific product versions or editions are not listed in the CVE data; any deployment of AOS‑CX should verify whether it is impacted by consulting HP's support documentation.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. EPSS score of <1% indicates a very low, yet non‑zero, exploitation probability, implying that while attacks are unlikely, they are still possible, but the issue is not included in the CISA KEV catalog. The attack vector requires that the attacker be authenticated and be able to send specially crafted requests to the vulnerable endpoint, suggesting that the threat is more likely to target insiders or compromised authentication services rather than open‑Internet attackers. Successful exploitation could allow the attacker to gain elevated privileges on the host, potentially compromising the entire AOS‑CX environment.
OpenCVE Enrichment