-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 HPE Networking Product Security Advisory ============================================== Advisory ID: HPESBNW05134 CVE: Please refer to the References section at the end of this advisory for the complete list of CVEs. Publication Date: 2026-Sep-01 Status: FINAL Last Updated: 2026-Sep-01 Severity: Critical Revision: 1 Title ===== Multiple Vulnerabilities in HPE Networking AOS-CX Summary ======= HPE Networking has released updates for AOS-CX that address multiple vulnerabilities described in this advisory. Affected Products ================= These vulnerabilities affect the following HPE Networking AOS-CX Versions unless specifically noted otherwise in the details section: - AOS-CX 10.18.0001 - AOS-CX 10.17.1021 and below - AOS-CX 10.16.1051 and below - AOS-CX 10.13.1180 and below - AOS-CX 10.10.1180 and below (EOM) NOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation. Unaffected Products =================== Any other HPE Networking products not specifically listed above are not affected by these vulnerabilities. Workaround ========== To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage. Exploitation and Public Discussion ================================== These vulnerabilities were generally discovered by internal security research at HPE Networking. HPE Networking is not aware of any public discussion or exploit code that targets the listed vulnerabilities as of the release date of this advisory. Customers are strongly urged to patch their instances due to the complexity, breadth, and impact of these vulnerabilities. Please note that due to the size of the Details and References sections, these sections have been moved to the end of the document to improve readability. Resolution ========== In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking AOS-CX software to one of the following versions (as applicable): - AOS-CX 10.18.1002 and above - AOS-CX 10.17.1030 and above - AOS-CX 10.16.1060 and above - AOS-CX 10.13.1190 and above - AOS-CX 10.10.1181 and above (EOM) NOTE: 10.10.x is EoM branch, and due to the branch's age and complexity, only internally identified Critical-severity vulnerabilities were addressed. Software versions with resolution/fixes for the disclosed Vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/. Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation. Revision History ================ Revision 1 / 2026-Sep-01 / Initial Publication HPE Networking SIRT Security Procedures ============================================= Complete information on reporting security vulnerabilities in HPE Networking products and obtaining assistance with security incidents is available at: https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us For reporting *NEW* HPE Networking security issues, email can be sent to networking-sirt(at)hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: https://www.hpe.com/info/psrt-pgp-key (c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information. Details ======= Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX (CVE-2026-73749) - ---------------------------------------------------------------- Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges. Internal References: VULN-291, VULN-294, VULN-293, VULN-356, VULN-781, VULN-820, VULN-957, VULN-826, VULN-295, VULN-301, VULN-353, VULN-727, VULN-737, VULN-776, VULN-822, VULN-823, VULN-824, VULN-821, VULN-784. Severity: Critical CVSS v3.1 Base Score: 9.8 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgements: These vulnerabilities were discovered by Internal security research at HPE Networking Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution (CVE-2026-73750) - ---------------------------------------------------------------- Vulnerabilities exist in a management module that may improperly process malformed or truncated input. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges. Internal References: VULN-299, VULN-753, VULN-801, VULN-736, VULN-750, VULN-774, VULN-832, VULN-773, VULN-347, VULN-768, VULN-800. Severity: High CVSS v3.1 Base Score: 8.8 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Authenticated Remote Command Injection in AOS-CX Web-based Management Interface (CVE-2026-73751) - ---------------------------------------------------------------- An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system. Internal References: VULN-762, VULN-953, VULN-817 Severity: High CVSS v3.1 Base Score: 8.8 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-CX (CVE-2026-73752) - ---------------------------------------------------------------- An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. Internal References: VULN-787, VULN-827 Severity: High CVSS v3.1 Base Score: 8.8 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface (CVE-2026-73753) - ---------------------------------------------------------------- Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system. Internal References: VULN-769, VULN-788, VULN-802, VULN-803 Severity: High CVSS v3.1 Base Score: 8.8 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Unauthenticated Format String Vulnerability leads to Remote Code Execution in AOS-CX (CVE-2026-73782) - ---------------------------------------------------------------- A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. Internal References: VULN-300 Severity: High CVSS v3.1 Base Score: 8.8 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-Based Management Interface (CVE-2026-73781) - ---------------------------------------------------------------- A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Internal References: VULN-833 Severity: High CVSS v3.1 Base Score: 8.4 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessions in AOS-CX (CVE-2026-73780) - ---------------------------------------------------------------- A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL. Internal References: VULN-746 Severity: High CVSS v3.1 Base Score: 8.3 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CX (CVE-2026-73779) - ---------------------------------------------------------------- Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information. Internal References: VULN-757, VULN-806, VULN-811, VULN-840 Severity: High CVSS v3.1 Base Score: 8.2 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Credential Manager Vulnerability Allows Unauthorized Administrative Access (CVE-2026-73778) - ---------------------------------------------------------------- A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process. Internal References: VULN-749 Severity: High CVSS v3.1 Base Score: 8.1 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API Endpoint (CVE-2026-73777) - ---------------------------------------------------------------- Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Internal References: VULN-807, VULN-810, VULN-813, VULN-819 Severity: High CVSS v3.1 Base Score: 8.1 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Authenticated Signature Verification Bypass Leading to Arbitrary Code Execution in AOS-CX (CVE-2026-73776) - ---------------------------------------------------------------- A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code on the underlying operating system, when certain pre-conditions outside of the attacker's control are met. Internal References: VULN-829 Severity: High CVSS v3.1 Base Score: 7.9 CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authenticated Sensitive Information Disclosure Vulnerabilities in AOS-CX (CVE-2026-73775) - ---------------------------------------------------------------- Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by AOS-CX. Internal References: VULN-725, VULN-726 Severity: High CVSS v3.1 Base Score: 7.7 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information Disclosure in AOS-CX (CVE-2026-73774) - ---------------------------------------------------------------- A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in limited disclosure or modification of information and disruption of the affected system. Internal References: VULN-341 Severity: High CVSS v3.1 Base Score: 7.6 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CX (CVE-2026-73773) - ---------------------------------------------------------------- An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service. Internal References: VULN-589, VULN-812 Severity: High CVSS v3.1 Base Score: 7.5 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgements: BUND (HPE Networking Bug Bounty Program) Improper Authentication Handling in AOS-CX Management Interface and API (CVE-2026-73771) - ---------------------------------------------------------------- An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface. Internal References: VULN-814, VULN-954 Severity: High CVSS v3.1 Base Score: 7.5 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authenticated Arbitrary File Write Vulnerability Leading to Remote Code Execution in AOS-CX (CVE-2026-73770) - ---------------------------------------------------------------- An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system. Internal References: VULN-754 Severity: High CVSS v3.1 Base Score: 7.3 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Local Privilege Escalation in AOS-CX Command Line Interface (CVE-2026-73768) - ---------------------------------------------------------------- A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges. Internal References: VULN-743 Severity: High CVSS v3.1 Base Score: 7.3 CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface (CVE-2026-73767) - ---------------------------------------------------------------- Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. Internal References: VULN-296, VULN-302, VULN-344, VULN-345, VULN-346, VULN-349, VULN-350, VULN-825, VULN-718, VULN-767, VULN-739, VULN-740, VULN-786. Severity: High CVSS v3.1 Base Score: 7.2 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Authenticated Command Injection Vulnerabilities in the API Endpoint of AOS-CX (CVE-2026-73766) - ---------------------------------------------------------------- Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Internal References: VULN-738, VULN-755, VULN-756, VULN-789, VULN-790, VULN-792, VULN-793, VULN-796, VULN-797, VULN-798, VULN-799, VULN-358, VULN-761, VULN-775, VULN-785, VULN-795, VULN-751, VULN-816, VULN-765, VULN-303, VULN-354, VULN-839, VULN-748, VULN-791, VULN-794, VULN-731. Severity: High CVSS v3.1 Base Score: 7.2 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Authenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in AOS-CX (CVE-2026-73765) - ---------------------------------------------------------------- Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution. Internal References: VULN-763, VULN-764, VULN-766 Severity: High CVSS v3.1 Base Score: 7.2 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Authentication Bypass Vulnerabilities Leading to Unauthorized Modification and Service Disruption in AOS-CX (CVE-2026-73764) - ---------------------------------------------------------------- Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services. Internal References: VULN-759, VULN-834 Severity: High CVSS v3.1 Base Score: 7.1 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Unauthenticated Remote Command Execution in Management Component (CVE-2026-73763) - ---------------------------------------------------------------- A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility. Internal Reference: VULN-841 Severity: High CVSS v3.1 Base Score: 7.1 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authorization Bypass in the API Endpoint of AOS-CX Leads to Unauthorized Access (CVE-2026-73762) - ---------------------------------------------------------------- A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy. Internal References: VULN-734 Severity: Medium CVSS v3.1 Base Score: 6.6 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Unauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX (CVE-2026-73772) - ---------------------------------------------------------------- Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying operating system. Internal References: VULN-729, VULN-340, VULN-741, VULN-742, VULN-772, VULN-777, VULN-780, VULN-782, VULN-783, VULN-804, VULN-805, VULN-809, VULN-836, VULN-837, VULN-838, VULN-842, VULN-348, VULN-342, VULN-343, VULN-956, VULN-955, VULN-297, VULN-352. Severity: Medium CVSS v3.1 Base Score: 6.5 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Unauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclosure in AOS-CX (CVE-2026-73761) - ---------------------------------------------------------------- An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system. Internal References: VULN-828 Severity: Medium CVSS v3.1 Base Score: 6.5 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authenticated Path Traversal Vulnerability Leads to Remote Unauthorized Access to Files in AOS-CX (CVE-2026-73760) - ---------------------------------------------------------------- An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files. Internal References: VULN-752 Severity: Medium CVSS v3.1 Base Score: 6.5 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Unauthenticated Denial-of-Service Vulnerabilities in AOS-CX (CVE-2026-73759) - ---------------------------------------------------------------- Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices. Internal References: VULN-728, VULN-760, VULN-771, VULN-779, VULN-808, VULN-298, VULN-359, VULN-730, VULN-744, VULN-745, VULN-747, VULN-778, VULN-815, VULN-818. Severity: Medium CVSS v3.1 Base Score: 6.5 CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Authenticated Privilege Escalation Vulnerability via Broken Access Control in AOS-CX (CVE-2026-73758) - ---------------------------------------------------------------- A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system. Internal References: VULN-843 Severity: Medium CVSS v3.1 Base Score: 6.5 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Authenticated Server-Side Request Forgery (SSRF) Leading to Information Disclosure in AOS-CX (CVE-2026-73757) - ---------------------------------------------------------------- A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and limited modification of sensitive information. Internal References: VULN-351 Severity: Medium CVSS v3.1 Base Score: 6.4 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Unauthenticated Sensitive Information Disclosure via Man-in-the- Middle Attack in AOS-CX via API Endpoint (CVE-2026-73756) - ---------------------------------------------------------------- A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system. Internal References: VULN-355 Severity: Medium CVSS v3.1 Base Score: 5.9 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Acknowledgements: This vulnerability was discovered by internal security research at HPE Networking Privilege Escalation via Unauthorized Access to Sensitive Session Information (CVE-2026-73755) - ---------------------------------------------------------------- A vulnerability in the logging component of AOS-CX may allow for unauthorized access to sensitive session information. Successful exploitation could result in a complete privilege escalation from an operator to an administrator role, allowing the attacker to perform administrative actions on the affected device. Internal References: VULN-374 Severity: Medium CVSS v3.1 Base Score: 5.7 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N Acknowledgements: Haxship1337 (HPE Networking Bug Bounty Program) Authenticated Denial-of-Service Vulnerabilities in the Command Line Interface of AOS-CX (CVE-2026-73754) - ---------------------------------------------------------------- Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system. Internal References: VULN-719, VULN-720, VULN-721, VULN-722 VULN-723, VULN-724, VULN-835 Severity: Medium CVSS v3.1 Base Score: 5.3 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking Authenticated Stack Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX (CVE-2026-73783) - ---------------------------------------------------------------- Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system. Internal References: VULN-732, VULN-733, VULN-735, VULN-758, VULN-770. Severity: Medium CVSS v3.1 Base Score: 4.9 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H Acknowledgements: These vulnerabilities were discovered by internal security research at HPE Networking References ========== CVE-2026-73749, CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, CVE-2026-73754, CVE-2026-73755, CVE-2026-73756, CVE-2026-73757, CVE-2026-73758, CVE-2026-73759, CVE-2026-73760, CVE-2026-73761, CVE-2026-73762, CVE-2026-73763, CVE-2026-73764, CVE-2026-73765, CVE-2026-73766, CVE-2026-73767, CVE-2026-73768, CVE-2026-73770, CVE-2026-73771, CVE-2026-73772, CVE-2026-73773, CVE-2026-73774, CVE-2026-73775, CVE-2026-73776, CVE-2026-73777, CVE-2026-73778, CVE-2026-73779, CVE-2026-73780, CVE-2026-73781, CVE-2026-73782, CVE-2026-73783. -----BEGIN PGP SIGNATURE----- iQHLBAEBCAA1FiEEQT1cq06WWXH+NEKru7x8adyj7A4FAmqRx/EXHHNlY3VyaXR5 LWFsZXJ0QGhwZS5jb20ACgkQu7x8adyj7A6CCwwAxYSdw8xRu8lAsrrgR30DoL4+ YT2k5OZfWIoRzRvmDDKLkO2usFWJrtYCcQMo4jAo1DjFkSf2OuewhqVDg3+7v6g3 SxxvSgy21NlVPKU/gbfWxS3aHeQpCWFq265OyGKIgXtForkdp6c6UDXmCSnkslez XLNxsEO+l0ARDfrgYcNN9OTTVqMng9cI+09AdbqBQrNH/0oX1wlln65WzHi2mWNd SQS5uO+uhWhkkHqfS3TfAu1Us65TJiqxOTnbqT0dvDs7zvQTE+UG9wIXJHtzxTk1 x7NGmDd5XPnVE7tuOYVTeL9iismGygjaLjmPX33XDGf4ODwwIlf3G1xnVgr8/Oyc pXKXLRej5X6yMehDYge+fEeL6rDVHsK2TcqH7CLgzZSoolqclEzONQDsjYSBATXM OeT5xDA0+GeHx+5guFicaQaEzRvN/a0xNdEqpasoEhqqSK4xdwGMR+ALV6Hw4p8I 0JUysqoh6fGdrD4s9ULS3c6QKnbfsW642zThb5q/ =h+mo -----END PGP SIGNATURE-----