Vulnerabilities
Vulnerable Software
Hpe:  Security Vulnerabilities
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
CVSS Score
7.2
EPSS Score
0.009
Published
2026-03-11
A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
CVSS Score
7.2
EPSS Score
0.012
Published
2026-03-11
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-03-11
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
CVSS Score
9.8
EPSS Score
0.007
Published
2026-03-11
A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.
CVSS Score
8.8
EPSS Score
0.006
Published
2026-03-11
A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).
CVSS Score
10.0
EPSS Score
0.01
Published
2026-03-02
Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-02-17
Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system configuration, as well as to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-02-17
An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or manipulate sensitive data.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-02-17
A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-02-17


Contact Us

Shodan ® - All rights reserved