cbcvebase.

Hpe Arubaos-Cx vulnerabilities

57 known vulnerabilities affecting hpe/arubaos-cx.

Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH37MEDIUM15LOW2

Vulnerabilities

Page 1 of 3
CVE-2026-73749P2CRITICALCVSS 9.8fixed in 10.10.1181≥ 10.13.0000, < 10.13.1190+3 more2026-09-01
CVE-2026-73749 [CRITICAL] CWE-284 CVE-2026-73749: Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malfo Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
nvd
CVE-2026-73778P2CRITICALCVSS 9.8≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73778 [CRITICAL] CWE-521 CVE-2026-73778: A vulnerability exists in the Credential Manager component that may allow for unauthorized administr A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successfu
nvd
CVE-2026-23813P2CRITICALCVSS 9.8fixed in 10.10.1180≥ 10.13.0000, < 10.13.1161+2 more2026-03-11
CVE-2026-23813 [CRITICAL] CWE-287 CVE-2026-23813: A vulnerability has been identified in the web-based management interface of AOS-CX switches that co A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
nvd
CVE-2026-23816P2HIGHCVSS 8.8fixed in 10.10.1180≥ 10.13.0000, < 10.13.1161+2 more2026-03-11
CVE-2026-23816 [HIGH] CWE-78 CVE-2026-23816: A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
nvd
CVE-2026-73750P2HIGHCVSS 8.8fixed in 10.10.1181≥ 10.13.0000, < 10.13.1190+3 more2026-09-01
CVE-2026-73750 [HIGH] CWE-284 CVE-2026-73750: Vulnerabilities exist in the authentication module that may improperly process malformed or truncate Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code
nvd
CVE-2026-73753P2HIGHCVSS 8.8fixed in 10.10.1181≥ 10.13.0000, < 10.13.1190+3 more2026-09-01
CVE-2026-73753 [HIGH] CWE-78 CVE-2026-73753: Exploitation through affected command-line operations could allow an authenticated low-privileged us Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2002-20001P3HIGHCVSS 7.5≥ 10.06.0000, < 10.06.0180≥ 10.07.0000, < 10.07.0030+2 more2021-11-11
CVE-2002-20001 [HIGH] CWE-400 CVE-2002-20001: The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arb The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disr
nvd
CVE-2023-3718P2HIGHCVSS 8.8≥ 10.10.0000, ≤ 10.10.1050≥ 10.11.0000, ≤ 10.11.10102023-08-01
CVE-2023-3718 [HIGH] CWE-77 CVE-2023-3718: An authenticated command injection vulnerability exists in the AOS-CX command line interface. Succe An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the d
nvd
CVE-2026-44880P2HIGHCVSS 8.8≤ 10.13.1170≥ 10.16.0000, ≤ 10.16.1050+2 more2026-07-21
CVE-2026-44880 [HIGH] CWE-120 CVE-2026-44880: A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploi A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
nvd
CVE-2026-73751P2HIGHCVSS 8.8fixed in 10.10.1181≥ 10.13.0000, < 10.13.1190+3 more2026-09-01
CVE-2026-73751 [HIGH] CWE-77 CVE-2026-73751: An authenticated user with low-privileged access could submit crafted input through the web-based ma An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
nvd
CVE-2025-37157P2HIGHCVSS 8.8≥ 10.10.0000, < 10.10.1170≥ 10.13.0000, < 10.13.1101+3 more2025-11-18
CVE-2025-37157 [HIGH] CWE-94 CVE-2025-37157: A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation cou A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
nvd
CVE-2025-37158P2HIGHCVSS 8.8≥ 10.10.0000, < 10.10.1170≥ 10.13.0000, < 10.13.1101+3 more2025-11-18
CVE-2025-37158 [HIGH] CWE-78 CVE-2025-37158: A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation cou A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
nvd
CVE-2026-23814P3HIGHCVSS 8.8fixed in 10.10.1180≥ 10.13.0000, < 10.13.1161+2 more2026-03-11
CVE-2026-23814 [HIGH] CWE-77 CVE-2026-23814: A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privileg A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.
nvd
CVE-2026-73763P3HIGHCVSS 8.8≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73763 [HIGH] CWE-77 CVE-2026-73763: A vulnerability exists in a management component that could allow an unauthenticated adjacent attack A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affected utility.
nvd
CVE-2021-41000P3HIGHCVSS 8.8≥ 10.06.0001, ≤ 10.06.0170≥ 10.07.0001, ≤ 10.07.0020+1 more2022-03-02
CVE-2021-41000 [HIGH] CWE-77 CVE-2021-41000: Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command l Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and bel
nvd
CVE-2023-1168P3HIGHCVSS 8.8≥ 10.06.0000, < 10.06.0240≥ 10.08.0000, ≤ 10.08.1070+2 more2023-03-22
CVE-2023-1168 [HIGH] CWE-77 CVE-2023-1168: An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engi An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.
nvd
CVE-2026-73777P3HIGHCVSS 8.1≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73777 [HIGH] CWE-287 CVE-2026-73777: Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially a Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.
nvd
CVE-2026-73752P3HIGHCVSS 8.8fixed in 10.10.1181≥ 10.13.0000, < 10.13.1190+3 more2026-09-01
CVE-2026-73752 [HIGH] CWE-22 CVE-2026-73752: An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successfu An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
nvd
CVE-2026-73782P3HIGHCVSS 8.8≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73782 [HIGH] CWE-134 CVE-2026-73782: A format string vulnerability exists in the command line interface of AOS-CX that could lead to unau A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
nvd
CVE-2026-73767P3HIGHCVSS 7.2≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73767 [HIGH] CWE-78 CVE-2026-73767: Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Succe Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
Hpe Arubaos-Cx vulnerabilities | cvebase