CVE-2026-76746 PUBLISHED

Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S

Assigner: hpe
Reserved: 19.08.2026 Published: 06.10.2026 Updated: 06.10.2026

An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
CVSS Score: 9.3

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product AOS-Switch (AOS-S)
Versions Default: affected
  • affected from 16.11.0000 to 16.11.0031 (incl.)

Credits

  • Internal security research (HPE Networking). reporter

References