5.9

CVE-2026-73756

Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API Endpoint

A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Arubaos-cx Version <= 10.10.1180
Hpe ≫ Arubaos-cx Version >= 10.13.0000 <= 10.13.1180
Hpe ≫ Arubaos-cx Version >= 10.16.0000 <= 10.16.1051
Hpe ≫ Arubaos-cx Version >= 10.17.0000 <= 10.17.1021
Hpe ≫ Arubaos-cx Version 10.18.0001
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.114
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
HPE 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US
Patch
Vendor Advisory