7.1

CVE-2026-73764

Authentication Bypass Vulnerabilities Leading to Unauthorized Modification and Service Disruption in AOS-CX

Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Arubaos-cx Version <= 10.10.1180
Hpe ≫ Arubaos-cx Version >= 10.13.0000 <= 10.13.1180
Hpe ≫ Arubaos-cx Version >= 10.16.0000 <= 10.16.1051
Hpe ≫ Arubaos-cx Version >= 10.17.0000 <= 10.17.1021
Hpe ≫ Arubaos-cx Version 10.18.0001
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.115
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
HPE 7.1 2.8 4.2
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US
Patch
Vendor Advisory