Impact
An operating system flaw in AOS-CX allows an attacker to trigger an out‑of‑bounds read by sending a specially crafted packet. The vulnerability is unauthenticated, meaning that any host on the network can send the payload and receive sensitive data from the underlying OS. The effect is the exposure of confidential system information that could aid further attacks. The weakness maps to CWE‑125 (Out‑of‑Bounds Read) and CWE‑200 (Information Exposure).
Affected Systems
Hewlett Packard Enterprise’s AOS‑CX platform is impacted. No specific version information is provided, so the issue may exist across all current releases until an official patch is released.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium‑severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, meaning that active exploitation data is limited. Because the flaw is unauthenticated, an attacker only needs to contact the device over the network to trigger the read; thus the attack surface is broad and the barrier to exploitation is low.
OpenCVE Enrichment