HPE Aruba Networking AOS-8 Unauthenticated Denial-of-Service Vulnerability in Network Management Service

Vulnerability

A denial-of-service vulnerability has been identified in the network management service of HPE Aruba Networking's AOS-8 Operating System. This vulnerability allows an unauthenticated remote attacker to disrupt normal device operations by sending specially crafted network packets to the affected device. Successful exploitation could cause the service process to terminate unexpectedly, leading to a denial-of-service condition.

Impact

Exploitation of this vulnerability can cause the affected service process to crash, disrupting normal device operations and management functions.

Remediation

Users can upgrade to AOS-8.13.1.2 or AOS-8.12.0.7 to address this vulnerability. AOS-8.10.0.22 also includes the patch. Instructions for downloading the update are available on the HPE Networking Support Portal.

Added: May 12, 2026, 9:04 PM
Updated: May 12, 2026, 9:04 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
0.6
exploitability
7.0
remediation
7.9
relevance
8.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.