Executive brief
A security vulnerability has been identified in the network management service of HPE Aruba Networking operating systems (AOS-8 and AOS-10). This service is responsible for managing and monitoring network infrastructure. An attacker could exploit this flaw to crash the management service or potentially take full control of the device, leading to network downtime or unauthorized access to the underlying system.
Technical details
A heap-based buffer overflow (CWE-122) exists within the Network Management service of HPE Aruba Networking AOS-8 and AOS-10. The vulnerability is reachable over the network without authentication (AV:N/PR:N). An attacker can exploit this by sending specially crafted packets to the affected service, leading to memory corruption. Successful exploitation can result in arbitrary code execution with elevated privileges on the underlying operating system or a denial-of-service (DoS) condition by crashing the impacted system process. Users are advised to refer to HPE advisory hpesbnw05048en_us for patching information.
Affected products
- HPE Aruba Networking AOS-10
- HPE Aruba Networking AOS-8
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory