Executive brief
HPE AOS-CX is a switching operating system used in enterprise network infrastructure. Multiple vulnerabilities in a daemon component can be exploited by unauthenticated remote attackers sending specially crafted network packets, potentially leading to remote code execution with elevated privileges and full system compromise.
Technical details
Multiple vulnerabilities exist in a daemon service within AOS-CX that fail to properly validate and process malformed input. The vulnerabilities are remotely exploitable without requiring authentication, triggered by sending specially crafted packets to the affected service. Successful exploitation allows remote code execution with elevated system privileges. The exact vulnerable component and root cause details are not publicly disclosed in the available reference materials.
Affected products
- HPE AOS-CX
Timeline
- 2026-09-01: disclosed