Impact
The vulnerability is a buffer overflow (CWE-120) in an underlying service of Hewlett Packard Enterprise AOS-CX that allows an unauthenticated attacker to send specially crafted packets and trigger a crash, causing the device to stop operating normally. The result is a disruption of the underlying operating system, which can interrupt network connectivity and business services.
Affected Systems
Hewlett Packard Enterprise AOS-CX. No specific versions are listed, so all releases before the fix are potentially affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker who can reach the device over the network can trigger the overflow without authentication or privileged access, leading to a denial of service of the entire underlying system.
OpenCVE Enrichment