Executive brief
HPE AOS-CX, the operating system for Aruba network switches, is affected by a security flaw in its command line interface. A user who already has high-level administrative access could exploit this to take full control of the underlying operating system. This could lead to a complete compromise of the network switch and any data passing through it.
Technical details
A buffer overflow vulnerability exists within the Command Line Interface (CLI) of HPE AOS-CX. The flaw is reachable over the network but requires the attacker to possess high-privileged credentials (PR:H). By providing specially crafted input to CLI commands, an authenticated attacker can trigger a memory corruption event to execute arbitrary code with root-level privileges on the underlying Linux-based operating system. The vulnerability affects multiple major release branches including 10.13, 10.16, 10.17, and 10.18. Users are advised to update to patched versions as specified in the HPE advisory.
Affected products
- HPE AOS-CX 10.13.0000 through 10.13.1170, 10.16.0000 through 10.16.1050, 10.17.0000 through 10.17.1020, 10.18.0000 before 10.18.0001
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory