Executive brief
HPE AOS-CX is a network operating system used in enterprise switches and routing equipment. A signature verification bypass in the command-line interface allows authenticated administrators to execute arbitrary code on the underlying operating system, potentially compromising network infrastructure and data flows through affected devices.
Technical details
A signature verification bypass vulnerability exists in the command-line interface (CLI) of HPE AOS-CX. The vulnerability allows an authenticated administrative user to circumvent code signing checks, enabling execution of arbitrary code on the underlying operating system. Exploitation requires administrative privileges and certain pre-conditions outside the attacker's control. The attack vector is local/adjacent network access through the CLI. Patches are expected from HPE via their support portal.
Affected products
- HPE AOS-CX
Timeline
- 2026-09-01: disclosed
- other: Not reported as exploited in the wild as of publication date