7.6highHigh
CVE-2026-73774
Hpe Arubaos-Cx
A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in limited disclosure or modification of information and disruption of the affected system.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable only from the same local or logical network.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.6 (v3.1)
- Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H- Weakness
- CWE-120
- Assigned by
- security-alert@hpe.com
Dates
- Published
- 2026-09-01
- Last modified
- 2026-09-04
- Sources
- NVD
Affected products
- Hpe Arubaos-Cx- 10.10.1180, 10.13.0000 - 10.13.1180, 10.16.0000 - 10.16.1051, 10.17.0000 - 10.17.1021, 10.18.0001
- Hpe Aruba Cx 10000-48y6c \(R8p13a\)all versions
- Hpe Aruba Cx 10000-48y6c \(R8p14a\)all versions
- Hpe Aruba Cx 10000-48y6c \(S0f98a\)all versions
- Hpe Aruba Cx 10040 \(S4r58a\)all versions
- Hpe Aruba Cx 10040 32p \(S4r54a\)all versions
- Hpe Aruba Cx 10040 32p \(S4r55a\)all versions
- Hpe Aruba Cx 10040 32p \(S4r56a\)all versions
- Hpe Aruba Cx 4100i 12-Port \(Jl817a\)all versions
- Hpe Aruba Cx 4100i 24-Port \(Jl818a\)all versions
- Hpe Aruba Cx 6000 12g \(R8n89a\)all versions
- Hpe Aruba Cx 6000 12p \(R8n89b\)all versions
As listed in the NVD configuration data. Not a statement about your estate.