Executive brief
AOS-CX is HPE's network operating system used in Arista switches and data center infrastructure. A vulnerability in its API endpoint allows remote attackers to bypass access controls and gain unauthorized access to management functions that should be restricted by policy, potentially leading to unauthorized configuration changes or data exposure.
Technical details
This vulnerability is an access control bypass in the AOS-CX API endpoint that fails to properly enforce configured access control policies. A remote attacker can exploit this flaw without authentication to circumvent restrictions and access management functionality that should be protected. The vulnerability allows unauthorized API calls to reach protected management endpoints, potentially enabling configuration modification, credential theft, or operational disruption. The attack vector is network-based with no user interaction required.
Affected products
- HPE AOS-CX
Timeline
- 2026-09-01: disclosed