VDB

GCVE-110-NCSC-2026-340

GCVE-110-NCSC-2026-340
Advisory PublishedCVSS 4.9/10
Vulnetix · Advisory published September 3, 2026
Multiple vulnerabilities in an AOS-CX daemon enable an unauthenticated remote attacker to send crafted packets that may result in remote code execution with elevated privileges.

Weaknesses (CWE)

CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-134Use of Externally-Controlled Format StringCWE-352Cross-Site Request Forgery (CSRF)CWE-521Weak Password RequirementsCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-73External Control of File Name or PathCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-125Out-of-bounds ReadCWE-918Server-Side Request Forgery (SSRF)CWE-121Stack-based Buffer Overflow

Risk Scores

CVSS 3.1
4.9/10
Medium · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
HPEvers:unknown/*
Aruba Networksvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›