Hpe Arubaos-Cx vulnerabilities
57 known vulnerabilities affecting hpe/arubaos-cx.
Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH37MEDIUM15LOW2
Vulnerabilities
Page 3 of 3
CVE-2026-73770P3HIGHCVSS 7.3≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73770 [HIGH] CWE-73 CVE-2026-73770: An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could
An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying ope
nvd
CVE-2026-73764P3HIGHCVSS 7.1≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73764 [HIGH] CWE-287 CVE-2026-73764: Vulnerabilities have been identified in the operating system of AOS-CX switches that could potential
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services.
nvd
CVE-2025-37160P3MEDIUMCVSS 6.5≥ 10.10.0000, < 10.10.1170≥ 10.13.0000, < 10.13.1101+3 more2025-11-18
CVE-2025-37160 [MEDIUM] CWE-200 CVE-2025-37160: A broken access control (BAC) vulnerability in the web-based management interface could allow an aut
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.
nvd
CVE-2026-73757P3MEDIUMCVSS 6.4≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73757 [MEDIUM] CWE-918 CVE-2026-73757: A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and limited modification of sensitive inf
nvd
CVE-2026-73762P3MEDIUMCVSS 6.6≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73762 [MEDIUM] CWE-284 CVE-2026-73762: A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to
A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control policy.
nvd
CVE-2026-73756P3MEDIUMCVSS 5.9≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73756 [MEDIUM] CWE-319 CVE-2026-73756: A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain
A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.
nvd
CVE-2026-23817P4MEDIUMCVSS 6.1≥ 10.06.0000, < 10.10.1180≥ 10.13.0000, < 10.13.1161+2 more2026-03-11
CVE-2026-23817 [MEDIUM] CWE-601 CVE-2026-23817: A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthentica
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
nvd
CVE-2026-73755P4MEDIUMCVSS 5.7≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73755 [MEDIUM] CWE-269 CVE-2026-73755: A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation c
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.
nvd
CVE-2025-37156P4MEDIUMCVSS 6.8≥ 10.10.0000, < 10.10.1170≥ 10.13.0000, < 10.13.1101+3 more2025-11-18
CVE-2025-37156 [MEDIUM] CVE-2025-37156: A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exp
A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.
nvd
CVE-2026-73772P4MEDIUMCVSS 6.5≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73772 [MEDIUM] CWE-120 CVE-2026-73772: Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unaut
Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying operating system.
nvd
CVE-2026-73761P4MEDIUMCVSS 6.5≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73761 [MEDIUM] CWE-125 CVE-2026-73761: An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could l
An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system.
nvd
CVE-2026-73759P4MEDIUMCVSS 6.5fixed in 10.10.1181≥ 10.13.0000, < 10.13.1190+3 more2026-09-01
CVE-2026-73759 [MEDIUM] CWE-400 CVE-2026-73759: Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.
nvd
CVE-2021-41003P4MEDIUMCVSS 6.1≥ 10.06.0001, ≤ 10.06.0170≥ 10.07.0001, ≤ 10.07.0050+2 more2022-03-02
CVE-2021-41003 [MEDIUM] CVE-2021-41003: Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interfa
Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07
nvd
CVE-2026-73754P4MEDIUMCVSS 5.3≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73754 [MEDIUM] CWE-400 CVE-2026-73754: Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploita
Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system.
nvd
CVE-2026-73783P4MEDIUMCVSS 4.9≤ 10.10.1180≥ 10.13.0000, ≤ 10.13.1180+3 more2026-09-01
CVE-2026-73783 [MEDIUM] CWE-121 CVE-2026-73783: Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could all
Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.
nvd
CVE-2024-54010P4LOWCVSS 3.4≥ 10.10.0000, < 10.13.1070≥ 10.14.0000, < 10.14.1030+1 more2025-01-08
CVE-2024-54010 [LOW] CWE-863 CVE-2024-54010: A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists.
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configuration
nvd
CVE-2025-25040P4LOWCVSS 3.3≥ 10.14.0000, < 10.14.1040≥ 10.15.0000, < 10.15.10012025-03-18
CVE-2025-25040 [LOW] CWE-863 CVE-2025-25040: A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the
A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects:
- AOS-CX 10.14.xxxx : All patches
- AOS-CX 10.15.xxxx : 10.15.1000 and below
The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to by
nvd
← Previous3 / 3