CVE-2026-23815

HIGH

AOS-CX Switches CLI - Command Injection

Title source: llm
STIX 2.1

Description

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

Scores

CVSS v3 7.2
EPSS 0.0094
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (4)
Hewlett Packard Enterprise (HPE)/AOS-CX 10.10.0000 - 10.10.1170
Hewlett Packard Enterprise (HPE)/AOS-CX 10.13.0000 - 10.13.1101
Hewlett Packard Enterprise (HPE)/AOS-CX 10.16.0000 - 10.16.1020
Hewlett Packard Enterprise (HPE)/AOS-CX 10.17.0000 - 10.17.0001
Published Mar 11, 2026
Tracked Since Mar 11, 2026