CVE-2026-23815

EUVD-2026-11075
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58.77%
Affected Products (NVD)
VendorProductVersion
hpearubaos-cx
𝑥
≤ 10.10.1170
hpearubaos-cx
10.13.0000 ≤
𝑥
≤ 10.13.1160
hpearubaos-cx
10.16.0000 ≤
𝑥
≤ 10.16.1020
hpearubaos-cx
10.17.0000 ≤
𝑥
≤ 10.17.0001
𝑥
= Vulnerable software versions