Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4244 articles · 196961 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-63454PATCHED
Hewlett Packard Enterprise (HPE) · AOS-CX

Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX

Description

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.

Affected Products

VendorProductVersions
Hewlett Packard Enterprise (HPE)AOS-CX10.17.0000, 10.16.0000, 10.13.0000, 10.18.0000

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arubaaos-cxcert_advisory90%

References

  • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05081en_us&docLocale=en_US

Related News (3 articles)

Tier B
BSI Advisories34d ago
[NEU] [hoch] Aruba AOS-CX: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR34d ago
Multiples vulnérabilités dans les produits HPE Aruba Networking (22 juillet 2026)
→ No new info (linked only)
Tier C
VulDB34d ago
CVE-2026-63454 | HPE AOS-CX up to 10.13.1180/10.16.1050/10.17.1020/10.18.0 command line interface path traversal
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.18.0001
PublishedJul 21, 2026
Last enriched34d agov2
Trending Score1
Source articles3
Independent3
Info Completeness8/14
Missing: epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63456
Authentication bypass via spoofed HTTP headers Orchestrator REST API
Trending: 7
CRITICALCVE-2026-63455
Authentication bypass via spoofed HTTP headers Orchestrator REST API
Trending: 7
MEDIUMCVE-2026-63457
CVE-2026-63457: A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
Trending: 4
HIGHCVE-2026-63453
Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Trending: 1
HIGHCVE-2026-44880
Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Trending: 1

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: affectedVersions
Jul 21, 2026
Patch Available
Jul 24, 2026

Version History

v2
Last enriched 34d ago
v2Tier C34d ago

Updated affected versions to specific patch levels (10.13.1180, 10.16.1050, 10.17.1020, 10.18.0), upgraded severity from HIGH to CRITICAL, and adjusted CVSS estimate accordingly.

affectedVersions
via VulDB
v134d ago

Initial creation