Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3435 articles · 210649 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-63453PATCHED
Hewlett Packard Enterprise (HPE) · AOS-CX

Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX

Description

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

Affected Products

VendorProductVersions
Hewlett Packard Enterprise (HPE)AOS-CX10.17.0000, 10.16.0000, 10.13.0000, 10.18.0000

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arubaaos-cxcert_advisory90%

References

  • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05081en_us&docLocale=en_US

Related News (3 articles)

Tier B
BSI Advisories45d ago
[NEU] [hoch] Aruba AOS-CX: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR46d ago
Multiples vulnérabilités dans les produits HPE Aruba Networking (22 juillet 2026)
→ No new info (linked only)
Tier C
VulDB46d ago
CVE-2026-63453 | HPE AOS-CX up to 10.13.1170/10.16.1050/10.17.1020/10.18.0 command line interface buffer overflow
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.18.0001
PublishedJul 21, 2026
Last enriched46d agov2
Trending Score0
Source articles3
Independent3
Info Completeness8/14
Missing: epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-73750
Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution
Trending: 37
HIGHCVE-2026-73773
Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CX
Trending: 34
HIGHCVE-2026-73780
Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessions in AOS-CX
Trending: 30
HIGHCVE-2026-73776
Authenticated Signature Verification Bypass Leading to Arbitrary Code Execution in AOS-CX
Trending: 30
HIGHCVE-2026-73779
Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CX
Trending: 30

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: affectedVersions
Jul 21, 2026
Patch Available
Jul 24, 2026

Version History

v2
Last enriched 46d ago
v2Tier C46d ago

Updated affected versions to more specific patch levels (10.13.1170, 10.16.1050, 10.17.1020, 10.18.0), changed severity from HIGH to CRITICAL, and adjusted CVSS estimate to 9.0 based on article's 'very critical' classification.

affectedVersions
via VulDB
v146d ago

Initial creation