Skip to content

Hewlett Packard Enterprise AOS-CX: buffer overflow

High7.2CVE-2026-63453 · Published Jul 21, 2026 · updated Aug 11, 2026

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

Affected versions

PackageAffectedFixed in
AOS-CX
Product
>= 10.17.0000, <= 10.17.1020No fix yet
>= 10.16.0000, <= 10.16.1050No fix yet
>= 10.13.0000, <= 10.13.1170No fix yet
>= 10.18.0000, < 10.18.000110.18.0001
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-120

More Hewlett Packard Enterprise advisories

All Hewlett Packard Enterprise
Advisory
Hewlett Packard Enterprise EdgeConnect: information disclosure
Critical9.8Aug 4
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway: insecure permissions
High7.2Jul 21
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway (ECOS): command injection
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: path traversal
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: buffer overflow
High8.8Jul 21
Hewlett Packard Enterprise HPE Networking Instant On: information disclosure
Medium6.5Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.