Sceawere

Vulnerability Detail

CVE-2026-73772UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AOS-CX Buffer Overflow DoS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
AOS-CX
Attack Type
N/A
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying operating system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-01T21:18:43.943Z",
  "pubdate": "2026-09-01T21:18:43.943Z",
  "executiveSummary": "A buffer overflow vulnerability exists within an underlying service of the AOS-CX operating system, allowing for an unauthenticated denial-of-service (DoS) condition.\nThe vulnerability resides in the way the affected service processes incoming packets, failing to adequately validate the length of input data before copying it into memory buffers.\nSuccessful exploitation results in the disruption of the AOS-CX operating system's normal operations, effectively rendering the network device unresponsive.\nThis flaw is remotely exploitable by an unauthenticated attacker, requiring only network reachability to the target device and the ability to transmit specially crafted packets.\nThe primary risk is the loss of availability of the networking infrastructure, which can have significant operational impacts on downstream services.\nNo elevated privileges or user interaction are required to execute the exploit, significantly lowering the barrier for entry for potential threat actors.\nOrganizations relying on AOS-CX should prioritize addressing this vulnerability to prevent potential service outages triggered by malicious network activity.",
  "technicalDetails": "The vulnerability is a memory corruption flaw specifically categorized as a buffer overflow, occurring within an underlying service of AOS-CX.\nThe root cause is a lack of rigorous bounds checking when handling incoming network packets destined for this service. When the service receives a specially crafted packet containing an oversized payload, it fails to perform sufficient validation on the length of the data before performing a memory copy operation, such as a stack or heap-based buffer write.\nThis leads to an overflow where the supplied data exceeds the allocated buffer size, overwriting adjacent memory regions. Depending on the target architecture and the specific memory layout of the affected service, this memory corruption can overwrite critical control data, such as return addresses, function pointers, or data structures necessary for service execution.\nThe exploitation flow begins with the attacker identifying the network-exposed service on the AOS-CX device. The attacker then constructs a malicious packet designed to trigger the overflow condition. By injecting a payload precisely crafted to exceed the buffer's capacity, the attacker can induce an unhandled exception or a crash condition.\nBecause the vulnerability occurs within an underlying system service, crashing this service often leads to the instability or complete cessation of the operating system's core network management or control plane functions. This causes the device to enter an unresponsive state, resulting in a denial-of-service condition where the device stops processing legitimate traffic or fails to maintain connectivity.\nExploitation does not require prior authentication, as the service processes these packets prior to the establishment of any session or authentication handshake. Furthermore, the attacker does not require any specific privilege level to initiate the attack, as the vulnerability is triggered through unauthenticated, remote packet injection.\nThe post-exploitation impact is limited to the disruption of availability. While buffer overflows can theoretically be leveraged for arbitrary code execution if memory control is achieved, the provided information emphasizes a denial-of-service outcome. The attack remains highly effective due to its simplicity and the critical nature of the underlying service affected within the AOS-CX environment."
}
CVE-2026-73772: AOS-CX Buffer Overflow DoS (MEDIUM Severity, CVSS: 6.5) - Sceawere