8.1
CVE-2026-73777
- EPSS 0.27%
- Veröffentlicht 01.09.2026 20:28:51
- Zuletzt bearbeitet 04.09.2026 14:53:31
- Erkennungen
Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API Endpoint
Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Arubaos-cx Version <= 10.10.1180
Hpe ≫ Arubaos-cx Version >= 10.13.0000 <= 10.13.1180
Hpe ≫ Arubaos-cx Version >= 10.16.0000 <= 10.16.1051
Hpe ≫ Arubaos-cx Version >= 10.17.0000 <= 10.17.1021
Hpe ≫ Arubaos-cx Version 10.18.0001
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.186 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HPE | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US