CVE-2026-23814
8.8Hewlett Packard Enterprise (HPE) · AOS-CX
A command injection vulnerability in the AOS-CX CLI allows authenticated remote attackers with low privileges to execute arbitrary commands, potentially leading to unauthorized system behavior.
Executive summary
A high-severity command injection vulnerability in HPE AOS-CX allows low-privilege authenticated attackers to compromise system integrity and availability.
Vulnerability
The flaw resides in the processing of command parameters within the AOS-CX Command Line Interface. An attacker with low-level authenticated access can manipulate these parameters to inject malicious commands, which are then executed by the system with elevated privileges.
Business impact
Successful exploitation poses a significant risk to network infrastructure, as it allows unauthorized command execution on critical networking hardware. Given the CVSS score of 8.8, this vulnerability could lead to total loss of confidentiality, integrity, and availability of the affected switch, potentially resulting in complete network disruption or unauthorized traffic redirection.
Remediation
Immediate Action: Review the official Hewlett Packard Enterprise security advisory and apply the recommended firmware updates or patches as soon as they are made available for your specific AOS-CX version.
Proactive Monitoring: Monitor device access logs for unusual CLI activity or repeated command failures that may indicate an attacker attempting to probe or exploit input parameters.
Compensating Controls: Restrict administrative access to the management interfaces of AOS-CX devices to trusted management networks or jump hosts to minimize the exposure of the CLI to potentially compromised user accounts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing HPE AOS-CX should prioritize this vulnerability due to the high potential for system compromise. Administrators must verify their current firmware versions against the affected list and establish a maintenance window to apply vendor-supplied patches immediately upon release to prevent unauthorized control of network hardware.
More Hewlett Packard Enterprise (HPE) CVEs
Sources
Originally found and disclosed by This vulnerability was discovered by the National Cybersecurity Agency of Italy (ACN)., per the CVE Program record.