CVE-2026-73764
massAuthentication bypass in HPE Aruba AOS-CX switch firmware
HPE has disclosed an improper authentication flaw (CWE-287) in the operating system of its Aruba AOS-CX network switches that allows an unauthenticated attacker to circumvent existing authentication controls. Although the description calls the actor remote, the CVSS 3.1 vector uses an adjacent attack vector (AV:A), so exploitation requires the attacker to be positioned on an adjacent network, such as the same LAN or management segment, rather than from the open internet. Successful exploitation does not disclose confidential data but enables unauthorized modification of affected resources and limited disruption of affected switch services, producing a CVSS 3.1 base score of 7.1 (high). Any organization running AOS-CX switch firmware covered by the HPE advisory is affected; the specific affected version ranges were not included in the available data. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns roughly a 0.2% probability of exploitation in the next 30 days, indicating no observed exploitation to date.
What to do: Inventory your AOS-CX switches and record current firmware versions, then check the HPE security advisory (CNA: [email protected]) for the list of affected releases and apply the patched firmware it specifies once available. In the interim, since the attack requires adjacent network access, restrict switch management interfaces to trusted administrative hosts via management VLANs and ACLs. No public exploit is known, so urgent out-of-band action is not required, but prioritize exposure review now.
| HPE Aruba AOS-CX switch operating system | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.