5.9
CVE-2026-73756
- EPSS 0.21%
- Veröffentlicht 01.09.2026 20:28:11
- Zuletzt bearbeitet 04.09.2026 14:59:41
- Erkennungen
Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API Endpoint
A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Arubaos-cx Version <= 10.10.1180
Hpe ≫ Arubaos-cx Version >= 10.13.0000 <= 10.13.1180
Hpe ≫ Arubaos-cx Version >= 10.16.0000 <= 10.16.1051
Hpe ≫ Arubaos-cx Version >= 10.17.0000 <= 10.17.1021
Hpe ≫ Arubaos-cx Version 10.18.0001
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.114 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HPE | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US