HPE
HPE Arubaos-cx: vulnerabilidades y CVE
HPE Arubaos-cx tiene 57 vulnerabilidades publicadas, 48 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE57
Últimos 12 meses48
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73782 | Alta (8.8) | 0.42% | — | 1 sept 2026 | A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute… |
| CVE-2026-73781 | Alta (8.4) | 0.51% | — | 1 sept 2026 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A… |
| CVE-2026-73779 | Alta (8.2) | 0.24% | — | 1 sept 2026 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could… |
| CVE-2026-73778 | Crítica (9.8) | 0.51% | — | 1 sept 2026 | A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or… |
| CVE-2026-73777 | Alta (8.1) | 0.46% | — | 1 sept 2026 | Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. |
| CVE-2026-73776 | Alta (7.9) | 0.12% | — | 1 sept 2026 | A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code… |
| CVE-2026-73775 | Alta (7.7) | 0.46% | — | 1 sept 2026 | Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could… |
| CVE-2026-73774 | Alta (7.6) | 0.29% | — | 1 sept 2026 | A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system.… |
| CVE-2026-73773 | Alta (7.5) | 0.46% | — | 1 sept 2026 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected… |
| CVE-2026-73772 | Media (6.5) | 0.29% | — | 1 sept 2026 | Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful… |
| CVE-2026-73771 | Alta (7.5) | 0.47% | — | 1 sept 2026 | An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific… |
| CVE-2026-73770 | Alta (7.3) | 0.24% | — | 1 sept 2026 | An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a… |
| CVE-2026-73768 | Alta (7.3) | 0.19% | — | 1 sept 2026 | A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges. |
| CVE-2026-73767 | Alta (7.2) | 1.7% | — | 1 sept 2026 | Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user… |
| CVE-2026-73766 | Alta (7.2) | 1.5% | — | 1 sept 2026 | Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker… |
| CVE-2026-73765 | Alta (7.2) | 0.87% | — | 1 sept 2026 | Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could… |
| CVE-2026-73764 | Alta (7.1) | 0.31% | — | 1 sept 2026 | Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could… |
| CVE-2026-73763 | Alta (8.8) | 0.47% | — | 1 sept 2026 | A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the… |
| CVE-2026-73762 | Media (6.6) | 0.29% | — | 1 sept 2026 | A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality… |
| CVE-2026-73761 | Media (6.5) | 0.28% | — | 1 sept 2026 | An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this… |
| CVE-2026-73760 | Media (6.5) | 0.56% | — | 1 sept 2026 | An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying… |
| CVE-2026-73758 | Media (6.5) | 0.30% | — | 1 sept 2026 | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system. |
| CVE-2026-73757 | Media (6.4) | 0.30% | — | 1 sept 2026 | A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate… |
| CVE-2026-73756 | Media (5.9) | 0.26% | — | 1 sept 2026 | A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data… |
| CVE-2026-73755 | Media (5.7) | 0.31% | — | 1 sept 2026 | A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information… |
| CVE-2026-73754 | Media (5.3) | 0.34% | — | 1 sept 2026 | Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system. |
| CVE-2026-73783 | Media (4.9) | 0.44% | — | 1 sept 2026 | Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system. |
| CVE-2026-73780 | Alta (8.3) | 0.20% | — | 1 sept 2026 | A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute… |
| CVE-2026-73759 | Media (6.5) | 0.29% | — | 1 sept 2026 | Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in… |
| CVE-2026-73753 | Alta (8.8) | 0.66% | — | 1 sept 2026 | Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de HPE
Edgeconnect Operating System · 38Integrated Lights-out 5 Firmware · 17Cloudline Cl4100 Gen10 Server Firmware · 16Cloudline Cl5800 Gen10 Server Firmware · 16Cloudline Cl5800 Gen9 Server Firmware · 16Cloudline Cl3100 Gen10 Server Firmware · 16Cloudline Cl5200 Gen9 Server Firmware · 16Baseboard Management Controller · 14Networking Instant ON · 12Insight Remote Support · 9Autopass License Server · 8Storeonce System · 8