Impact
The vulnerability is a buffer overflow that permits an unauthenticated attacker in proximity to an AOS‑S switch to read arbitrary memory regions, potentially revealing sensitive data, and can cause the device to crash, resulting in a denial of service. The flaw arises from an improper restriction of operations within the bounds of a memory buffer, leading to both information disclosure and service interruption.
Affected Systems
Hewlett Packard Enterprise AOS‑Switch (AOS‑S). No specific version numbers were provided, so all versions of the AOS‑S platform remain potentially affected.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity, reflecting full confidentiality, integrity, and availability impact. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified, but the absence of a KEV listing suggests no known active exploits. The likely attack vector involves an attacker located adjacent to the device—such as on the same local network segment or with physical proximity—exploiting the adjacent buffer overflow without requiring authentication. If exploited, an attacker could expose memory contents and destabilize the switch, disrupting network operations.
OpenCVE Enrichment