Authenticated Path Traversal Vulnerability in AOS-CX by HPE
CVE-2026-63454
7.2HIGH
What is CVE-2026-63454?
An authenticated path traversal vulnerability has been identified in AOS-CX, a network operating system by HPE. This security flaw permits attackers, once they've authenticated, to leverage the command line interface of the underlying operating system to copy arbitrary files to locations accessible by users. This may facilitate further exploitation of the system, including the potential for remote code execution, thereby jeopardizing the confidentiality, integrity, and availability of the data.
Affected Version(s)
AOS-CX 10.17.0000 <= 10.17.1020
AOS-CX 10.17.0000 <= 10.17.1020
AOS-CX 10.16.0000 <= 10.16.1050
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was discovered by moonv through the HPE Aruba Networking Bug Bounty program.
