CVE-2026-76747 PUBLISHED

Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S

Assigner: hpe
Reserved: 19.08.2026 Published: 06.10.2026 Updated: 06.10.2026

Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS Score: 9.1

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product AOS-Switch (AOS-S)
Versions Default: affected
  • affected from 16.11.0000 to 16.11.0031 (incl.)

Credits

  • Internal security research (HPE Networking). reporter

References