Our takeHPE fixed a critical unauthenticated RCE (CVSS 9.8) in AOS-CX. Update your switches now if you run this yourself; most lean-IT teams get it through a managed service and can ask their provider.Cyber Resilience desk
Sources (10)
- auscert_bulletins · auscert_bulletins
- auscert_bulletins · auscert_bulletins
- auscert_bulletins · auscert_bulletins
- auscert_bulletins · auscert_bulletins
- auscert_bulletins · auscert_bulletins
- auscert_bulletins · auscert_bulletins
- auscert_bulletins · auscert_bulletins
- auscert_bulletins · auscert_bulletins
- auscert_bulletins · auscert_bulletins
- auscert_bulletins · auscert_bulletins
What this means for you — Security leader:Apply the HPE patch for AOS-CX switches immediately (CVSS 9.8 unauthenticated RCE). Check your inventory for affected versions and test in a maintenance window.
What this means for you — Lean IT orgs:If you run HPE Networking switches, update the AOS-CX firmware now. Most small teams can schedule this during the next maintenance window; the rest can ignore it.
What this means for you — MSP:Audit all client environments for HPE AOS-CX switches and push the vendor patch (CVSS 9.8). Prioritize any exposed to the internet.
What this means for you — Researcher:HPE released an advisory for a critical unauthenticated RCE in AOS-CX (CVSS 9.8). Patch and monitor for exploitation.