Executive brief
A vulnerability in the AOS-8 operating system, used in HPE networking devices, could allow an attacker to crash a critical network management service. By sending specially crafted network packets, an unauthorized user can cause the device to stop functioning correctly, leading to a service outage. This disruption can impact network availability and administrative operations until the service is restored.
Technical details
A denial-of-service vulnerability exists in a network management service within the HPE AOS-8 Operating System. The flaw is categorized as CWE-770 (Allocation of Resources Without Limits or Throttling), where the service fails to properly handle specifically crafted network packets. An unauthenticated remote attacker can exploit this by sending malicious traffic over the network, causing the affected service process to terminate unexpectedly. This results in a loss of availability for the management component and potentially disrupts broader device operations. The vulnerability has been assigned a CVSS v3.1 base score of 7.5.
Affected products
- HPE AOS-8 Operating System
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory