7.2
HIGH CVSS 3.1
CVE-2026-63454
Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX
Description

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.

INFO

Published Date :

July 21, 2026, 7:17 p.m.

Last Modified :

Aug. 11, 2026, 5:57 p.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2026-63454 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Hpe arubaos-cx
2 Hpe aruba_cx_10000-48y6c_\(r8p13a\)
3 Hpe aruba_cx_10000-48y6c_\(r8p14a\)
4 Hpe aruba_cx_10000-48y6c_\(s0f98a\)
5 Hpe aruba_cx_10040_\(s4r58a\)
6 Hpe aruba_cx_10040_32p_\(s4r54a\)
7 Hpe aruba_cx_10040_32p_\(s4r55a\)
8 Hpe aruba_cx_10040_32p_\(s4r56a\)
9 Hpe aruba_cx_4100i_12-port_\(jl817a\)
10 Hpe aruba_cx_4100i_24-port_\(jl818a\)
11 Hpe aruba_cx_6000_12g_\(r8n89a\)
12 Hpe aruba_cx_6000_12p_\(r8n89b\)
13 Hpe aruba_cx_6000_12p_\(s4r21a\)
14 Hpe aruba_cx_6000_24g_\(r8n87a\)
15 Hpe aruba_cx_6000_24g_\(r8n88a\)
16 Hpe aruba_cx_6000_24p_\(r8n87b\)
17 Hpe aruba_cx_6000_24p_\(r8n88b\)
18 Hpe aruba_cx_6000_24p_\(s4r26a\)
19 Hpe aruba_cx_6000_24p_\(s4r27a\)
20 Hpe aruba_cx_6000_48g_\(r8n85a\)
21 Hpe aruba_cx_6000_48g_\(r8n86a\)
22 Hpe aruba_cx_6000_48g_\(r9y03a\)
23 Hpe aruba_cx_6000_48p_\(r8n85b\)
24 Hpe aruba_cx_6000_48p_\(r8n86b\)
25 Hpe aruba_cx_6000_48p_\(r9y03b\)
26 Hpe aruba_cx_6000_48p_\(s4r20a\)
27 Hpe aruba_cx_6000_48p_\(s4r24a\)
28 Hpe aruba_cx_6000_48p_\(s4r25a\)
29 Hpe aruba_cx_6000_8p_\(s4r22a\)
30 Hpe aruba_cx_6000_8p_\(s4r23a\)
31 Hpe aruba_cx_6000_8p_\(s4r28a\)
32 Hpe aruba_cx_6000_8p_\(s4r29a\)
33 Hpe aruba_cx_6100_12g_\(jl679a\)
34 Hpe aruba_cx_6100_24g_\(jl677a\)
35 Hpe aruba_cx_6100_24g_\(jl678a\)
36 Hpe aruba_cx_6100_48g_\(jl675a\)
37 Hpe aruba_cx_6100_48g_\(jl676a\)
38 Hpe aruba_cx_6100_48g_\(r9y04a\)
39 Hpe aruba_cx_6200f_12g_\(r8q72a\)
40 Hpe aruba_cx_6200f_12g_\(r8v13a\)
41 Hpe aruba_cx_6200f_24g_\(jl724b\)
42 Hpe aruba_cx_6200f_24g_\(jl725b\)
43 Hpe aruba_cx_6200f_24g_\(s0g13a\)
44 Hpe aruba_cx_6200f_24g_\(s0g14a\)
45 Hpe aruba_cx_6200f_24g_\(s0m81a\)
46 Hpe aruba_cx_6200f_24g_\(s0m82a\)
47 Hpe aruba_cx_6200f_24g_\(s0m86a\)
48 Hpe aruba_cx_6200f_24g_\(s0m87a\)
49 Hpe aruba_cx_6200f_48g_\(jl726b\)
50 Hpe aruba_cx_6200f_48g_\(jl727b\)
51 Hpe aruba_cx_6200f_48g_\(jl728b\)
52 Hpe aruba_cx_6200f_48g_\(s0g15a\)
53 Hpe aruba_cx_6200f_48g_\(s0g16a\)
54 Hpe aruba_cx_6200f_48g_\(s0g17a\)
55 Hpe aruba_cx_6200f_48g_\(s0m83a\)
56 Hpe aruba_cx_6200f_48g_\(s0m84a\)
57 Hpe aruba_cx_6200f_48g_\(s0m85a\)
58 Hpe aruba_cx_6200f_48g_\(s0m88a\)
59 Hpe aruba_cx_6200f_48g_\(s0m89a\)
60 Hpe aruba_cx_6200f_48g_\(s0m90a\)
61 Hpe aruba_cx_6200m_24g_\(r8q67a\)
62 Hpe aruba_cx_6200m_24g_\(r8q68a\)
63 Hpe aruba_cx_6200m_24g_\(r8v08a\)
64 Hpe aruba_cx_6200m_24g_\(r8v09a\)
65 Hpe aruba_cx_6200m_36g_\(r8q71a\)
66 Hpe aruba_cx_6200m_36g_\(r8v12a\)
67 Hpe aruba_cx_6200m_48g_\(r8q69a\)
68 Hpe aruba_cx_6200m_48g_\(r8q70a\)
69 Hpe aruba_cx_6200m_48g_\(r8v10a\)
70 Hpe aruba_cx_6200m_48g_\(r8v11a\)
71 Hpe aruba_cx_6300f_24_\(jl666a\)
72 Hpe aruba_cx_6300f_24_\(jl668a\)
73 Hpe aruba_cx_6300f_24p_\(s0g96a\)
74 Hpe aruba_cx_6300f_24p_\(s0g98a\)
75 Hpe aruba_cx_6300f_48_\(jl665a\)
76 Hpe aruba_cx_6300f_48_\(jl667a\)
77 Hpe aruba_cx_6300f_48p_\(s0g95a\)
78 Hpe aruba_cx_6300f_48p_\(s0g97a\)
79 Hpe aruba_cx_6300m_16p_\(s4p41a\)
80 Hpe aruba_cx_6300m_16p_\(s4p45a\)
81 Hpe aruba_cx_6300m_24_\(jl658a\)
82 Hpe aruba_cx_6300m_24_\(jl660a\)
83 Hpe aruba_cx_6300m_24_\(jl662a\)
84 Hpe aruba_cx_6300m_24_\(jl664a\)
85 Hpe aruba_cx_6300m_24p_\(r8s89a\)
86 Hpe aruba_cx_6300m_24p_\(r8s92a\)
87 Hpe aruba_cx_6300m_24p_\(s0f99a\)
88 Hpe aruba_cx_6300m_24p_\(s0g01a\)
89 Hpe aruba_cx_6300m_24p_\(s0g03a\)
90 Hpe aruba_cx_6300m_24p_\(s0g05a\)
91 Hpe aruba_cx_6300m_24p_\(s4p44a\)
92 Hpe aruba_cx_6300m_24p_\(s4p48a\)
93 Hpe aruba_cx_6300m_24p_\(s5z46a\)
94 Hpe aruba_cx_6300m_32p_\(s4p42a\)
95 Hpe aruba_cx_6300m_32p_\(s4p46a\)
96 Hpe aruba_cx_6300m_48_\(jl659a\)
97 Hpe aruba_cx_6300m_48_\(jl661a\)
98 Hpe aruba_cx_6300m_48_\(jl663a\)
99 Hpe aruba_cx_6300m_48_\(jl762a\)
100 Hpe aruba_cx_6300m_48p_\(r8s90a\)
101 Hpe aruba_cx_6300m_48p_\(s0g00a\)
102 Hpe aruba_cx_6300m_48p_\(s0g02a\)
103 Hpe aruba_cx_6300m_48p_\(s0g04a\)
104 Hpe aruba_cx_6300m_48p_\(s0g06a\)
105 Hpe aruba_cx_6300m_48p_\(s0x44a\)
106 Hpe aruba_cx_6300m_48p_\(s4p43a\)
107 Hpe aruba_cx_6300m_48p_\(s4p47a\)
108 Hpe aruba_cx_6300m_48sr5_\(r8s91a\)
109 Hpe aruba_cx_6405_\(r0x26a\)
110 Hpe aruba_cx_6405_48sfp\+8sfp56_\(r0x30a\)
111 Hpe aruba_cx_6405_96g_\(r0x29a\)
112 Hpe aruba_cx_6405_v2_\(r0x26c\)
113 Hpe aruba_cx_6410_\(r0x27a\)
114 Hpe aruba_cx_6410_96g_\(jl741a\)
115 Hpe aruba_cx_6410_v2_\(r0x27c\)
116 Hpe aruba_cx_8320_32_\(jl579a\)
117 Hpe aruba_cx_8320_48_\(jl479a\)
118 Hpe aruba_cx_8320_48_\(jl581a\)
119 Hpe aruba_cx_8325-32c_\(jl626a\)
120 Hpe aruba_cx_8325-32c_\(jl627a\)
121 Hpe aruba_cx_8325-48y8c_\(jl624a\)
122 Hpe aruba_cx_8325-48y8c_\(jl625a\)
123 Hpe aruba_cx_8325-48y8c_\(jl858a\)
124 Hpe aruba_cx_8325h-16c_\(s4b22a\)
125 Hpe aruba_cx_8325h-16c_\(s4b24a\)
126 Hpe aruba_cx_8325h-18y4c_\(s4b21a\)
127 Hpe aruba_cx_8325h-18y4c_\(s4b23a\)
128 Hpe aruba_cx_8325p-32c_\(s0g07a\)
129 Hpe aruba_cx_8325p-32c_\(s0g08a\)
130 Hpe aruba_cx_8360-12c_\(jl708c\)
131 Hpe aruba_cx_8360-12c_\(jl709c\)
132 Hpe aruba_cx_8360-16y2c_\(jl702c\)
133 Hpe aruba_cx_8360-16y2c_\(jl703c\)
134 Hpe aruba_cx_8360-24xf2c_\(jl710c\)
135 Hpe aruba_cx_8360-24xf2c_\(jl711c\)
136 Hpe aruba_cx_8360-32y4c_\(jl700c\)
137 Hpe aruba_cx_8360-32y4c_\(jl701c\)
138 Hpe aruba_cx_8360-48xt4c_\(jl706c\)
139 Hpe aruba_cx_8360-48xt4c_\(jl707c\)
140 Hpe aruba_cx_8360-48y6c_\(jl704c\)
141 Hpe aruba_cx_8360-48y6c_\(jl705c\)
142 Hpe aruba_cx_8400_\(jl376a\)
143 Hpe aruba_cx_8400_8-slot_chassis_\(jl375a\)
144 Hpe aruba_cx_9300_\(r8z97a\)
145 Hpe aruba_cx_9300_\(r8z98a\)
146 Hpe aruba_cx_9300_\(r8z99a\)
147 Hpe aruba_cx_9300_\(r9a00a\)
148 Hpe aruba_cx_9300_32d_\(r8z96a\)
149 Hpe aruba_cx_9300_32d_\(r9a29a\)
150 Hpe aruba_cx_9300_32d_\(r9a30a\)
151 Hpe aruba_cx_9300s_32p_\(s0f81a\)
152 Hpe aruba_cx_9300s_32p_\(s0f82a\)
153 Hpe aruba_cx_9300s_32p_\(s0f83a\)
154 Hpe aruba_cx_9300s_32p_\(s0f84a\)
155 Hpe aruba_cx_9300s_32p_\(s0f87a\)
156 Hpe aruba_cx_9300s_32p_\(s0f88a\)
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 HIGH eb103674-0d28-4225-80f8-39fb86215de0
CVSS 3.1 HIGH [email protected]
Solution
Apply security updates to fix the authenticated path traversal vulnerability.
  • Update AOS-CX to the latest security version.
  • Restrict unauthorized file access.
  • Implement input validation for file operations.
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-63454.

URL Resource
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05081en_us&docLocale=en_US Vendor Advisory
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-63454 is associated with the following CWEs:

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-63454 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-63454 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Aug. 11, 2026

    Action Type Old Value New Value
    Added CPE Configuration AND OR *cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:* versions from (including) 10.16.0000 up to (including) 10.16.1050 *cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:* versions from (including) 10.17.0000 up to (including) 10.17.1020 *cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:* versions from (including) 10.18.0000 up to (including) 10.18.0001 *cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:* versions up to (including) 10.13.1170 OR cpe:2.3:h:hpe:aruba_cx_10000-48y6c_(r8p13a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_10000-48y6c_(r8p14a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_10000-48y6c_(s0f98a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_10040_(s4r58a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_10040_32p_(s4r54a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_10040_32p_(s4r55a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_10040_32p_(s4r56a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_4100i_12-port_(jl817a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_4100i_24-port_(jl818a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_12g_(r8n89a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_12p_(r8n89b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_12p_(s4r21a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_24g_(r8n87a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_24g_(r8n88a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_24p_(r8n87b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_24p_(r8n88b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_24p_(s4r26a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_24p_(s4r27a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_48g_(r8n85a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_48g_(r8n86a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_48g_(r9y03a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_48p_(r8n85b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_48p_(r8n86b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_48p_(r9y03b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_48p_(s4r20a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_48p_(s4r24a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_48p_(s4r25a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_8p_(s4r22a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_8p_(s4r23a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_8p_(s4r28a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6000_8p_(s4r29a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6100_12g_(jl679a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6100_24g_(jl677a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6100_24g_(jl678a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6100_48g_(jl675a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6100_48g_(jl676a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6100_48g_(r9y04a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_12g_(r8q72a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_12g_(r8v13a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_24g_(jl724b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_24g_(jl725b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_24g_(s0g13a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_24g_(s0g14a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_24g_(s0m81a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_24g_(s0m82a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_24g_(s0m86a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_24g_(s0m87a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(jl726b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(jl727b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(jl728b):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(s0g15a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(s0g16a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(s0g17a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(s0m83a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(s0m84a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(s0m85a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(s0m88a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(s0m89a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200f_48g_(s0m90a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_24g_(r8q67a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_24g_(r8q68a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_24g_(r8v08a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_24g_(r8v09a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_36g_(r8q71a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_36g_(r8v12a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_48g_(r8q69a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_48g_(r8q70a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_48g_(r8v10a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6200m_48g_(r8v11a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300f_24_(jl666a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300f_24_(jl668a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300f_24p_(s0g96a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300f_24p_(s0g98a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300f_48_(jl665a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300f_48_(jl667a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300f_48p_(s0g95a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300f_48p_(s0g97a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_16p_(s4p41a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_16p_(s4p45a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24_(jl658a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24_(jl660a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24_(jl662a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24_(jl664a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24p_(r8s89a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24p_(r8s92a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24p_(s0f99a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24p_(s0g01a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24p_(s0g03a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24p_(s0g05a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24p_(s4p44a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24p_(s4p48a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_24p_(s5z46a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_32p_(s4p42a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_32p_(s4p46a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48_(jl659a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48_(jl661a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48_(jl663a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48_(jl762a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48p_(r8s90a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48p_(s0g00a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48p_(s0g02a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48p_(s0g04a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48p_(s0g06a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48p_(s0x44a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48p_(s4p43a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48p_(s4p47a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6300m_48sr5_(r8s91a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6405_(r0x26a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6405_48sfp+8sfp56_(r0x30a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6405_96g_(r0x29a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6405_v2_(r0x26c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6410_(r0x27a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6410_96g_(jl741a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_6410_v2_(r0x27c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8320_32_(jl579a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8320_48_(jl479a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8320_48_(jl581a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325-32c_(jl626a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325-32c_(jl627a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325-48y8c_(jl624a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325-48y8c_(jl625a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325-48y8c_(jl858a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325h-16c_(s4b22a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325h-16c_(s4b24a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325h-18y4c_(s4b21a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325h-18y4c_(s4b23a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325p-32c_(s0g07a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8325p-32c_(s0g08a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-12c_(jl708c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-12c_(jl709c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-16y2c_(jl702c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-16y2c_(jl703c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-24xf2c_(jl710c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-24xf2c_(jl711c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-32y4c_(jl700c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-32y4c_(jl701c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-48xt4c_(jl706c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-48xt4c_(jl707c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-48y6c_(jl704c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8360-48y6c_(jl705c):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8400_(jl376a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_8400_8-slot_chassis_(jl375a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300_(r8z97a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300_(r8z98a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300_(r8z99a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300_(r9a00a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300_32d_(r8z96a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300_32d_(r9a29a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300_32d_(r9a30a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300s_32p_(s0f81a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300s_32p_(s0f82a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300s_32p_(s0f83a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300s_32p_(s0f84a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300s_32p_(s0f87a):-:*:*:*:*:*:*:* cpe:2.3:h:hpe:aruba_cx_9300s_32p_(s0f88a):-:*:*:*:*:*:*:*
    Added Reference Type Hewlett Packard Enterprise (HPE): https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05081en_us&docLocale=en_US Types: Vendor Advisory
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 24, 2026

    Action Type Old Value New Value
    Changed SSVC {'id': 'CVE-2026-63454', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-22T19:05:05.582247Z'} {'id': 'CVE-2026-63454', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-23T00:00:00+00:00'}
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 22, 2026

    Action Type Old Value New Value
    Added CWE CWE-22
    Added SSVC {'id': 'CVE-2026-63454', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-22T19:05:05.582247Z'}
  • New CVE Received by [email protected]

    Jul. 21, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'Hewlett Packard Enterprise (HPE)', 'product': 'AOS-CX', 'versions': [{'status': 'affected', 'version': '10.17.0000', 'versionType': 'semver', 'lessThanOrEqual': '10.17.1020'}, {'status': 'affected', 'version': '10.16.0000', 'versionType': 'semver', 'lessThanOrEqual': '10.16.1050'}, {'status': 'affected', 'version': '10.13.0000', 'versionType': 'semver', 'lessThanOrEqual': '10.13.1180'}, {'status': 'affected', 'version': '10.18.0000', 'lessThan': '10.18.0001', 'versionType': 'semver'}], 'defaultStatus': 'affected'}]
    Added Description An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
    Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Added Reference https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05081en_us&docLocale=en_US
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.