Impact
AOS‑CX devices can be forced into a non‑responsive state by a remote actor that sends specially crafted network packets, triggering a denial‑of‑service condition. The vulnerability allows impact without requiring authentication or elevated privileges, meaning any externally reachable device is at risk. The primary consequence is the disruption of device availability; there is no direct impact to confidentiality or integrity as the failure is purely functional.
Affected Systems
Hewlett Packard Enterprise AOS‑CX devices are affected. The CNA list does not specify firmware or software versions, so all available releases of AOS‑CX are considered vulnerable until an official update is issued. The vulnerability can be exploited on any deployed appliance regardless of its specific configuration.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high risk level. Exploitation is possible via remote network traffic, with no authentication or special privileges required. The EPSS score is < 1%, indicating a very low but non‑zero probability of active exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploit activity has been observed. The likely attack vector is remote packet injection, whereby an adversary sends crafted packets across the network to trigger the denial‑of‑service condition.
OpenCVE Enrichment