Impact
The vulnerability is a classic buffer overflow in an AOS‑S interface, allowing an unauthenticated attacker to run arbitrary code. A successful exploit could give an attacker full control over the device, compromising confidentiality, integrity, and availability of the network switching fabric. This is a CWE‑120 weakness, representing an unchecked buffer copy that leads to memory corruption and remote code execution.
Affected Systems
The affected product is Hewlett Packard Enterprise’s AOS‑S Switch. No specific firmware or software version ranges were disclosed, so any instance of the AOS‑S Switch that has not yet been confirmed to include the patch may be vulnerable.
Risk and Exploitability
The vendor assigns a CVSS score of 9.8, indicating critical severity. The EPSS score is not available, but the lack of inclusion in CISA’s KEV catalog means no confirmed exploits have been observed publicly. The likely attack vector is the remote, unauthenticated network interface that the buffer overflow resides on, allowing an attacker to reach the device from outside the local network.
OpenCVE Enrichment