Impact
A buffer overflow in the underlying operating system of AOS-CX can be triggered by an unauthenticated attacker who sends specially crafted packets. The overflow may allow the attacker to read or modify sensitive information, and in some cases cause the system to become unavailable. The vulnerability is a type of buffer overflow that leads to information exposure and limited control over the target system as stated in the description.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise AOS‑CX. No specific product versions are listed; any deployment of AOS‑CX may be impacted.
Risk and Exploitability
The CVSS score of 7.6 places this issue in the high severity range, while the EPSS score of 0.00191 indicates a very low but nonzero exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be unauthenticated network access, requiring the attacker only to send crafted packets to the target without authentication. Conditions for exploitation appear to be the receipt of malformed network traffic, which could be performed by any host on the same network as the AOS‑CX device.
OpenCVE Enrichment