CVE-2026-73771
largeAuthentication bypass/DoS flaw in HPE ArubaOS-CX management interface and API
HPE (acting as CNA) has disclosed an improper-authentication flaw (CWE-287) in the management interface and API of AOS-CX (ArubaOS-CX), the operating system running on HPE Aruba enterprise switches. An unauthenticated remote attacker could send requests that, under specific conditions (the published CVSS vector notes high attack complexity, meaning exploitation depends on conditions beyond the attacker's control), are mishandled by authentication processing. Successful exploitation could let the attacker bypass authentication and gain unauthorized access to the management interface, or exhaust system resources and cause a denial of service, with high impact to confidentiality, integrity, and availability. Organizations running AOS-CX switches whose management interface or REST API is reachable from untrusted networks are the affected population. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days, so no active exploitation is currently known.
What to do: Review HPE's security advisory for CVE-2026-73771 and upgrade AOS-CX switches to the fixed firmware releases listed there (affected version ranges are not included in the data available here). Until patched, restrict the management interface and REST API to trusted management networks using management VLANs, ACLs, or firewall rules, and disable or limit API access where it is not required. With no public PoC, no KEV listing, and EPSS at 0.3%, there is no evidence of in-the-wild exploitation, but remediation should still be scheduled at the next maintenance window.
| HPE ArubaOS-CX (AOS-CX switch operating system — management interface and API) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.