Executive brief
AOS-CX is a network operating system used in switches and routers to manage enterprise network traffic and connectivity. A denial-of-service vulnerability in its command-line interface allows authenticated users to crash or hang the device, disrupting network operations until the system is restarted.
Technical details
A denial-of-service vulnerability exists in the command-line interface (CLI) of HPE AOS-CX that can be triggered by an authenticated user executing specific commands. The vulnerability allows an attacker with CLI access to cause the system to become unresponsive or crash, disrupting normal device operations. This requires prior authentication to the device, limiting exposure to authorized personnel or those with valid credentials. An authenticated attacker can exploit this flaw to cause service disruption but cannot achieve code execution, privilege escalation, or data exfiltration. Patches or mitigations may be available through HPE support.
Affected products
- HPE AOS-CX <UNKNOWN>
Timeline
- 2026-09-01: disclosed