9.8
CVE-2026-73749
- EPSS 0.49%
- Veröffentlicht 01.09.2026 20:28:01
- Zuletzt bearbeitet 22.09.2026 20:55:15
- Erkennungen
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Arubaos-cx Version < 10.10.1181
Hpe ≫ Arubaos-cx Version >= 10.13.0000 < 10.13.1190
Hpe ≫ Arubaos-cx Version >= 10.16.0000 < 10.16.1060
Hpe ≫ Arubaos-cx Version >= 10.17.0000 < 10.17.1030
Hpe ≫ Arubaos-cx Version 10.18.0001
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.401 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| HPE | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US