cbcvebase.

Hewlett Packard Enterprise Aos-Cx vulnerabilities

46 known vulnerabilities affecting hewlett_packard_enterprise/aos-cx.

Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH27MEDIUM14LOW2

Vulnerabilities

Page 1 of 3
CVE-2026-73749P2CRITICALCVSS 9.8≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73749 [CRITICAL] CWE-284 CVE-2026-73749: Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malfo Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
nvd
CVE-2026-73778P2CRITICALCVSS 9.8≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73778 [CRITICAL] CWE-521 CVE-2026-73778: A vulnerability exists in the Credential Manager component that may allow for unauthorized administr A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successfu
nvd
CVE-2026-23813P2CRITICALCVSS 9.8≥ 10.17.0000, ≤ 10.17.0001≥ 10.16.0000, ≤ 10.16.1020+2 more2026-03-11
CVE-2026-23813 [CRITICAL] CWE-287 CVE-2026-23813: A vulnerability has been identified in the web-based management interface of AOS-CX switches that co A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
nvd
CVE-2026-23816P2HIGHCVSS 8.8≥ 10.17.0000, ≤ 10.17.0001≥ 10.16.0000, ≤ 10.16.1020+2 more2026-03-11
CVE-2026-23816 [HIGH] CWE-78 CVE-2026-23816: A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
nvd
CVE-2026-73750P2HIGHCVSS 8.8≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73750 [HIGH] CWE-284 CVE-2026-73750: Vulnerabilities exist in the authentication module that may improperly process malformed or truncate Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code
nvd
CVE-2026-73753P2HIGHCVSS 8.8≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73753 [HIGH] CWE-78 CVE-2026-73753: Exploitation through affected command-line operations could allow an authenticated low-privileged us Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2026-44880P2HIGHCVSS 8.8≥ 10.17.0000, ≤ 10.17.1020≥ 10.16.0000, ≤ 10.16.1050+2 more2026-07-21
CVE-2026-44880 [HIGH] CWE-120 CVE-2026-44880: A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploi A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
nvd
CVE-2026-73751P2HIGHCVSS 8.8≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73751 [HIGH] CWE-77 CVE-2026-73751: An authenticated user with low-privileged access could submit crafted input through the web-based ma An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
nvd
CVE-2026-23814P3HIGHCVSS 8.8≥ 10.17.0000, ≤ 10.17.0001≥ 10.16.0000, ≤ 10.16.1020+2 more2026-03-11
CVE-2026-23814 [HIGH] CWE-77 CVE-2026-23814: A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privileg A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.
nvd
CVE-2026-73763P3HIGHCVSS 8.8≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73763 [HIGH] CWE-77 CVE-2026-73763: A vulnerability exists in a management component that could allow an unauthenticated adjacent attack A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility.
nvd
CVE-2026-73777P3HIGHCVSS 8.1≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73777 [HIGH] CWE-287 CVE-2026-73777: Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially a Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.
nvd
CVE-2026-73752P3HIGHCVSS 8.8≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73752 [HIGH] CWE-22 CVE-2026-73752: An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successfu An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
nvd
CVE-2026-73782P3HIGHCVSS 8.8≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73782 [HIGH] CWE-134 CVE-2026-73782: A format string vulnerability exists in the command line interface of AOS-CX that could lead to unau A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
nvd
CVE-2026-73767P3HIGHCVSS 7.2≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73767 [HIGH] CWE-78 CVE-2026-73767: Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Succe Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2026-73766P3HIGHCVSS 7.2≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73766 [HIGH] CWE-77 CVE-2026-73766: Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2026-73765P3HIGHCVSS 7.2≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73765 [HIGH] CWE-22 CVE-2026-73765: Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitati Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
nvd
CVE-2026-73775P3HIGHCVSS 7.7≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73775 [HIGH] CWE-200 CVE-2026-73775: Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low p Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by AOS-CX.
nvd
CVE-2026-73771P3HIGHCVSS 7.5≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73771 [HIGH] CWE-287 CVE-2026-73771: An authentication vulnerability exists in the AOS-CX management interface and API that may allow imp An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or
nvd
CVE-2026-63454P3HIGHCVSS 7.2≥ 10.17.0000, ≤ 10.17.1020≥ 10.16.0000, ≤ 10.16.1050+2 more2026-07-21
CVE-2026-63454 [HIGH] CWE-22 CVE-2026-63454: An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vuln An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
nvd
CVE-2026-23815P3HIGHCVSS 7.2≥ 10.17.0000, ≤ 10.17.0001≥ 10.16.0000, ≤ 10.16.1020+2 more2026-03-11
CVE-2026-23815 [HIGH] CWE-77 CVE-2026-23815: A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
nvd
Hewlett Packard Enterprise Aos-Cx vulnerabilities | cvebase