HPE Aruba Networking AOS-CX Authenticated Privilege Escalation Vulnerability in SSH Restricted Shell

Vulnerability

A vulnerability exists in the SSH restricted shell interface of HPE Aruba Networking AOS-CX software, specifically in versions 10.16.1000 and below, 10.15.1020 and below, 10.14.1050 and below, 10.13.1090 and below, and 10.10.1160 and below. This vulnerability allows authenticated read-only users to bypass access controls and gain administrator privileges on the affected system.

Impact

Exploitation of this vulnerability could lead to unauthorized administrative access on the affected system.

Remediation

Users can upgrade to HPE Aruba Networking AOS-CX versions 10.16.1001 and above, 10.15.1030 and above, 10.14.1060 and above, 10.13.1101 and above, or 10.10.1170 and above. These updated versions include the necessary fixes for this vulnerability.

Added: Nov 18, 2025, 7:31 PM
Updated: Nov 18, 2025, 10:25 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
3.5
remediation
7.9
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.