cbcvebase.

Hewlett Packard Enterprise Aos-Cx vulnerabilities

46 known vulnerabilities affecting hewlett_packard_enterprise/aos-cx.

Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH27MEDIUM14LOW2

Vulnerabilities

Page 2 of 3
CVE-2026-73780P3HIGHCVSS 8.3≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73780 [HIGH] CWE-352 CVE-2026-73780: A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a spec
nvd
CVE-2026-63453P3HIGHCVSS 7.2≥ 10.17.0000, ≤ 10.17.1020≥ 10.16.0000, ≤ 10.16.1050+2 more2026-07-21
CVE-2026-63453 [HIGH] CWE-120 CVE-2026-63453: Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitati Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
nvd
CVE-2026-73760P3MEDIUMCVSS 6.5≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73760 [MEDIUM] CWE-22 CVE-2026-73760: An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vuln An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files.
nvd
CVE-2026-73779P3HIGHCVSS 8.2≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73779 [HIGH] CWE-269 CVE-2026-73779: Vulnerabilities have been identified in the operating system of AOS-CX switches that could potential Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information.
nvd
CVE-2026-73781P3HIGHCVSS 8.4≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73781 [HIGH] CWE-79 CVE-2026-73781: A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
nvd
CVE-2026-73776P3HIGHCVSS 7.9≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73776 [HIGH] CWE-347 CVE-2026-73776: A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Succes A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code on the underlying operating system, when certain pre-conditions outside of the attacker’s control are met.
nvd
CVE-2026-73774P3HIGHCVSS 7.6≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73774 [HIGH] CWE-120 CVE-2026-73774: A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in limited disclosure or modification of information and disruption of the affe
nvd
CVE-2026-73773P3HIGHCVSS 7.5≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73773 [HIGH] CWE-400 CVE-2026-73773: An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Succe An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
nvd
CVE-2026-73768P3HIGHCVSS 7.3≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73768 [HIGH] CWE-20 CVE-2026-73768: A vulnerability exists in the command line interface of AOS-CX that may allow for improper processin A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges.
nvd
CVE-2026-73758P3MEDIUMCVSS 6.5≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73758 [MEDIUM] CWE-269 CVE-2026-73758: A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation c A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
nvd
CVE-2026-73770P3HIGHCVSS 7.3≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73770 [HIGH] CWE-73 CVE-2026-73770: An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying ope
nvd
CVE-2026-73764P3HIGHCVSS 7.1≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73764 [HIGH] CWE-287 CVE-2026-73764: Vulnerabilities have been identified in the operating system of AOS-CX switches that could potential Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services.
nvd
CVE-2026-73757P3MEDIUMCVSS 6.4≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73757 [MEDIUM] CWE-918 CVE-2026-73757: A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and limited modification of sensitive inf
nvd
CVE-2026-73762P3MEDIUMCVSS 6.6≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73762 [MEDIUM] CWE-284 CVE-2026-73762: A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy.
nvd
CVE-2026-73756P3MEDIUMCVSS 5.9≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73756 [MEDIUM] CWE-319 CVE-2026-73756: A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.
nvd
CVE-2026-23817P4MEDIUMCVSS 6.1≥ 10.17.0000, ≤ 10.17.0001≥ 10.16.0000, ≤ 10.16.1020+2 more2026-03-11
CVE-2026-23817 [MEDIUM] CWE-601 CVE-2026-23817: A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthentica A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
nvd
CVE-2026-73755P4MEDIUMCVSS 5.7≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73755 [MEDIUM] CWE-269 CVE-2026-73755: A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation c A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.
nvd
CVE-2026-73772P4MEDIUMCVSS 6.5≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73772 [MEDIUM] CWE-120 CVE-2026-73772: Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unaut Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying operating system.
nvd
CVE-2026-73761P4MEDIUMCVSS 6.5≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73761 [MEDIUM] CWE-125 CVE-2026-73761: An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could l An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system.
nvd
CVE-2026-73759P4MEDIUMCVSS 6.5≥ 10.18.0000, ≤ 10.18.0001≥ 10.17.0000, ≤ 10.17.1021+3 more2026-09-01
CVE-2026-73759 [MEDIUM] CWE-400 CVE-2026-73759: Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial- Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.
nvd
Hewlett Packard Enterprise Aos-Cx vulnerabilities | cvebase