Executive brief
HPE AOS-CX is a network operating system used in data center switches. An authentication vulnerability in its management interface and API allows unauthenticated remote attackers to bypass security controls or trigger denial of service attacks under specific conditions, potentially leading to unauthorized access to network infrastructure or service disruption.
Technical details
An authentication processing vulnerability exists in the AOS-CX management interface and API that fails to properly validate incoming requests under specific conditions. The vulnerability is remotely exploitable without requiring prior authentication, allowing an attacker to either bypass authentication controls or exhaust system resources. Successful exploitation can grant unauthorized administrative access to the management interface or cause denial of service. HPE has published security guidance available through their support portal (hpesbnw05134en_us).
Affected products
- HPE AOS-CX <UNKNOWN>
Timeline
- 2026-09-01: disclosed