Executive brief
AOS-CX is a network switch operating system used in enterprise environments to manage data center and campus infrastructure. An authenticated attacker with CLI access can inject arbitrary commands that execute with elevated privileges on the underlying system, potentially compromising the integrity and availability of the network infrastructure.
Technical details
Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. The vulnerability allows an attacker with valid CLI credentials to inject and execute arbitrary operating system commands with privileged user context. The attack requires prior authentication to the device's management interface. Successful exploitation enables arbitrary command execution on the underlying operating system, which could lead to full device compromise, data exfiltration, or denial of service. Fix availability should be confirmed via HPE/Aruba security advisories.
Affected products
- HPE Aruba AOS-CX
Timeline
- 2026-09-01: disclosed