Skip to content

Hewlett Packard Enterprise AOS-CX: path traversal

High7.2CVE-2026-63454 · Published Jul 21, 2026 · updated Aug 11, 2026

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.

Affected versions

PackageAffectedFixed in
AOS-CX
Product
>= 10.17.0000, <= 10.17.1020No fix yet
>= 10.16.0000, <= 10.16.1050No fix yet
>= 10.13.0000, <= 10.13.1180No fix yet
>= 10.18.0000, < 10.18.000110.18.0001
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More Hewlett Packard Enterprise advisories

All Hewlett Packard Enterprise
Advisory
Hewlett Packard Enterprise EdgeConnect: information disclosure
Critical9.8Aug 4
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway: insecure permissions
High7.2Jul 21
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway (ECOS): command injection
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: buffer overflow
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: buffer overflow
High8.8Jul 21
Hewlett Packard Enterprise HPE Networking Instant On: information disclosure
Medium6.5Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.