Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
| Vendor | Product | Versions |
|---|---|---|
| Hewlett Packard Enterprise (HPE) | AOS-CX | 10.17.0000, 10.16.0000, 10.13.0000, 10.18.0000 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| aruba | aos-cx | cert_advisory | 90% |
Updated affected versions to more specific patch levels (10.13.1170, 10.16.1050, 10.17.1020, 10.18.0), changed severity from HIGH to CRITICAL, and adjusted CVSS estimate to 9.0 based on article's 'very critical' classification.
Initial creation