Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4252 articles · 196976 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-44880PATCHED
hewlett packard enterprise (hpe) · aos-cx

Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX

Description

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

Affected Products

VendorProductVersions
hewlett packard enterprise (hpe)aos-cx10.17.0000, 10.16.0000, 10.13.0000, 10.18.0000

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arubaaos-cxcert_advisory90%

References

  • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05081en_us&docLocale=en_US

Related News (3 articles)

Tier B
BSI Advisories34d ago
[NEU] [hoch] Aruba AOS-CX: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR34d ago
Multiples vulnérabilités dans les produits HPE Aruba Networking (22 juillet 2026)
→ No new info (linked only)
Tier C
VulDB34d ago
CVE-2026-44880 | HPE AOS-CX up to 10.13.1170/10.16.1050/10.17.1020/10.18.0 command line interface buffer overflow
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.18.0001
PublishedJul 21, 2026
Last enriched34d agov2
Trending Score1
Source articles3
Independent3
Info Completeness8/14
Missing: epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63456
Authentication bypass via spoofed HTTP headers Orchestrator REST API
Trending: 7
CRITICALCVE-2026-63455
Authentication bypass via spoofed HTTP headers Orchestrator REST API
Trending: 7
MEDIUMCVE-2026-63457
CVE-2026-63457: A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
Trending: 4
HIGHCVE-2026-63454
Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX
Trending: 1
HIGHCVE-2026-63453
Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: affectedVersions, severity
Jul 21, 2026
Patch Available
Jul 24, 2026

Version History

v2
Last enriched 34d ago
v2Tier C34d ago

Updated affected versions to include specific patch levels (10.13.1170, 10.16.1050, 10.17.1020, 10.18.0) and corrected severity from HIGH to CRITICAL

affectedVersionsseverity
via VulDB
v134d ago

Initial creation