« Volver al listado

HPE

HPE Arubaos-cx: vulnerabilidades y CVE

HPE Arubaos-cx tiene 57 vulnerabilidades publicadas, 48 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE57
Últimos 12 meses48
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-73782Alta (8.8)0.42%—1 sept 2026
A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute…
CVE-2026-73781Alta (8.4)0.51%—1 sept 2026
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A…
CVE-2026-73779Alta (8.2)0.24%—1 sept 2026
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could…
CVE-2026-73778Crítica (9.8)0.51%—1 sept 2026
A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or…
CVE-2026-73777Alta (8.1)0.46%—1 sept 2026
Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.
CVE-2026-73776Alta (7.9)0.12%—1 sept 2026
A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code…
CVE-2026-73775Alta (7.7)0.46%—1 sept 2026
Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could…
CVE-2026-73774Alta (7.6)0.29%—1 sept 2026
A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system.…
CVE-2026-73773Alta (7.5)0.46%—1 sept 2026
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected…
CVE-2026-73772Media (6.5)0.29%—1 sept 2026
Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful…
CVE-2026-73771Alta (7.5)0.47%—1 sept 2026
An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific…
CVE-2026-73770Alta (7.3)0.24%—1 sept 2026
An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a…
CVE-2026-73768Alta (7.3)0.19%—1 sept 2026
A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges.
CVE-2026-73767Alta (7.2)1.7%—1 sept 2026
Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user…
CVE-2026-73766Alta (7.2)1.5%—1 sept 2026
Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker…
CVE-2026-73765Alta (7.2)0.87%—1 sept 2026
Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could…
CVE-2026-73764Alta (7.1)0.31%—1 sept 2026
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could…
CVE-2026-73763Alta (8.8)0.47%—1 sept 2026
A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the…
CVE-2026-73762Media (6.6)0.29%—1 sept 2026
A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality…
CVE-2026-73761Media (6.5)0.28%—1 sept 2026
An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this…
CVE-2026-73760Media (6.5)0.56%—1 sept 2026
An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying…
CVE-2026-73758Media (6.5)0.30%—1 sept 2026
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
CVE-2026-73757Media (6.4)0.30%—1 sept 2026
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate…
CVE-2026-73756Media (5.9)0.26%—1 sept 2026
A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data…
CVE-2026-73755Media (5.7)0.31%—1 sept 2026
A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information…
CVE-2026-73754Media (5.3)0.34%—1 sept 2026
Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system.
CVE-2026-73783Media (4.9)0.44%—1 sept 2026
Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.
CVE-2026-73780Alta (8.3)0.20%—1 sept 2026
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute…
CVE-2026-73759Media (6.5)0.29%—1 sept 2026
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in…
CVE-2026-73753Alta (8.8)0.66%—1 sept 2026
Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services21
  2. T1059 Command and Scripting Interpreter20
  3. T1190 Exploit Public-Facing Application5
  4. T1078 Valid Accounts4
  5. T1203 Exploitation for Client Execution4
  6. T1068 Exploitation for Privilege Escalation3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de HPE