Impact
AOS‑CX can be brought to a non‑responsive state by an unauthenticated remote actor that sends specially crafted network packets. The vulnerability is triggered without any prior authentication or elevated privileges, and the result is a disruption of device availability; confidentiality and integrity are not directly affected.
Affected Systems
Hewlett Packard Enterprise AOS‑CX devices are impacted. No specific firmware or software version list is provided, so all current releases are considered vulnerable until a vendor‑issued update is available.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate to high risk, and the exploitability is facilitated by remote network traffic with no authentication required. EPSS information is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred from the description as remote packet injection: a malicious actor could target the device from outside the local network by sending crafted packets to the affected protocol to trigger a denial‑of‑service condition.
OpenCVE Enrichment