Impact
Stack overflow vulnerabilities have been identified in a specific API endpoint of Hewlett Packard Enterprise’s AOS-CX. These flaws occur when input data exceeds the buffer that holds execution stack information, causing a stack corruption that eventually terminates the affected process. The CVE description confirms that an authenticated attacker can trigger the overflow and subsequently disrupt service availability on the targeted system. The weakness corresponds to a classic stack-based buffer overflow, which is often labeled as a low‑level memory corruption issue that can lead to denial of service without enabling code execution.
Affected Systems
The vulnerability impacts the Hewlett Packard Enterprise AOS‑CX product line. No specific version numbers are listed in the CNA data, so all deployments of AOS‑CX that expose the affected API endpoint should be considered potentially vulnerable until the vendor issues a patch. Verification of product revision and configuration is necessary to confirm exposure.
Risk and Exploitability
The CVSS score of 4.9 places this issue in the medium severity range. Exploitation requires the attacker to be authenticated, implying that only users with legitimate credentials or compromised accounts can leverage the flaw. Because the attack vector is insider‑or‑compromised‑user level, the real‑world risk depends on how tightly the API is secured and the overall privilege model of the AOS‑CX environment. EPSS data is unavailable, and the vulnerability is not listed in KEV, suggestive of limited public exploitation activity to date. Nonetheless, the possibility of a denial‑of‑service event from a known authenticated user makes it prudent to address the weakness promptly.
OpenCVE Enrichment