ZeroHour

CVE-2026-73771

large

Authentication bypass/DoS flaw in HPE ArubaOS-CX management interface and API

CVSS 3.1
7.5 high
EPSS
<1%p22
Published
()
Modified
AI analysis

HPE (acting as CNA) has disclosed an improper-authentication flaw (CWE-287) in the management interface and API of AOS-CX (ArubaOS-CX), the operating system running on HPE Aruba enterprise switches. An unauthenticated remote attacker could send requests that, under specific conditions (the published CVSS vector notes high attack complexity, meaning exploitation depends on conditions beyond the attacker's control), are mishandled by authentication processing. Successful exploitation could let the attacker bypass authentication and gain unauthorized access to the management interface, or exhaust system resources and cause a denial of service, with high impact to confidentiality, integrity, and availability. Organizations running AOS-CX switches whose management interface or REST API is reachable from untrusted networks are the affected population. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days, so no active exploitation is currently known.

What to do: Review HPE's security advisory for CVE-2026-73771 and upgrade AOS-CX switches to the fixed firmware releases listed there (affected version ranges are not included in the data available here). Until patched, restrict the management interface and REST API to trusted management networks using management VLANs, ACLs, or firewall rules, and disable or limit API access where it is not required. With no public PoC, no KEV listing, and EPSS at 0.3%, there is no evidence of in-the-wild exploitation, but remediation should still be scheduled at the next maintenance window.

Affected
HPE ArubaOS-CX (AOS-CX switch operating system — management interface and API)
Estimated exposure
largelikely hundreds of thousands of AOS-CX switches deployed, of which a subset (probably tens of thousands) have management interfaces or APIs reachable from… — AOS-CX is HPE Aruba's operating system across its enterprise campus and datacenter switch product lines, implying an installed base in the hundreds of thousands of devices, while switch management interfaces are typically confined to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.