Description
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code.
Published: 2026-10-06
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a classic buffer overflow in an AOS‑S interface, allowing an unauthenticated attacker to run arbitrary code. A successful exploit could give an attacker full control over the device, compromising confidentiality, integrity, and availability of the network switching fabric. This is a CWE‑120 weakness, representing an unchecked buffer copy that leads to memory corruption and remote code execution.

Affected Systems

The affected product is Hewlett Packard Enterprise’s AOS‑S Switch. No specific firmware or software version ranges were disclosed, so any instance of the AOS‑S Switch that has not yet been confirmed to include the patch may be vulnerable.

Risk and Exploitability

The vendor assigns a CVSS score of 9.8, indicating critical severity. The EPSS score is not available, but the lack of inclusion in CISA’s KEV catalog means no confirmed exploits have been observed publicly. The likely attack vector is the remote, unauthenticated network interface that the buffer overflow resides on, allowing an attacker to reach the device from outside the local network.

Generated by OpenCVE AI on October 6, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the AOS‑S Switch firmware to the latest release that includes the buffer overflow fix.
  • Restrict access to the vulnerable interface by applying network segmentation or firewall rules so that only trusted hosts can reach it.
  • Enable detailed logging on the switch and regularly monitor for anomalous activity that may indicate exploitation attempts.

Generated by OpenCVE AI on October 6, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code.
Title Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-10-06T19:06:34.931Z

Reserved: 2026-08-19T16:13:34.636Z

Link: CVE-2026-76744

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:29.727

Modified: 2026-10-06T20:17:29.727

Link: CVE-2026-76744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:30:07Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')