7.5highHigh
CVE-2026-73771
Hpe Arubaos-Cx
An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
- To exploit it, no account is needed.
- Beyond that, someone has to be persuaded to take an action first.
Scoring
- CVSS
- 7.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H- Weakness
- CWE-287
- Assigned by
- security-alert@hpe.com
Dates
- Published
- 2026-09-01
- Last modified
- 2026-09-04
- Sources
- NVD
Affected products
- Hpe Arubaos-Cx- 10.10.1180, 10.13.0000 - 10.13.1180, 10.16.0000 - 10.16.1051, 10.17.0000 - 10.17.1021, 10.18.0001
- Hpe Aruba Cx 10000-48y6c \(R8p13a\)all versions
- Hpe Aruba Cx 10000-48y6c \(R8p14a\)all versions
- Hpe Aruba Cx 10000-48y6c \(S0f98a\)all versions
- Hpe Aruba Cx 10040 \(S4r58a\)all versions
- Hpe Aruba Cx 10040 32p \(S4r54a\)all versions
- Hpe Aruba Cx 10040 32p \(S4r55a\)all versions
- Hpe Aruba Cx 10040 32p \(S4r56a\)all versions
- Hpe Aruba Cx 4100i 12-Port \(Jl817a\)all versions
- Hpe Aruba Cx 4100i 24-Port \(Jl818a\)all versions
- Hpe Aruba Cx 6000 12g \(R8n89a\)all versions
- Hpe Aruba Cx 6000 12p \(R8n89b\)all versions
As listed in the NVD configuration data. Not a statement about your estate.