ZeroHour

CVE-2026-73773

mass

Unauthenticated DoS in the API of HPE ArubaOS-CX Switches

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-73773 is an unauthenticated denial-of-service vulnerability in the API endpoint of HPE's ArubaOS-CX network operating system, which runs on HPE Aruba's CX-series campus and data center switches. An attacker with network reachability to the switch's API can send requests that disrupt the normal operation of the affected service, with no privileges or user interaction required (CVSS 3.1: AV:N/AC:L/PR:N/UI:N) and no confidentiality or integrity impact; the CWE-400 classification suggests resource-exhaustion behavior. Organizations running ArubaOS-CX with the API interface enabled are potentially affected; the provided data does not specify affected version ranges, so defenders should confirm scope against HPE's advisory. Exploitation has not been observed: the flaw is not in CISA's KEV catalog, EPSS assigns a low ~0.3% probability of exploitation within 30 days, and no public proof-of-concept is known.

What to do: Inventory ArubaOS-CX switches in your estate, review HPE's advisory for the list of affected and fixed releases, and upgrade to the fixed firmware from the HPE support portal during the next maintenance window. Until patched, restrict reachability of the switch API (management interface) to trusted management networks using ACLs or out-of-band management, and disable the API on devices that do not use it. Given low EPSS and no known public PoC or in-the-wild exploitation, routine prioritized patching is proportionate.

Affected
HPE ArubaOS-CX
Estimated exposure
mass≈10^5–10^6 switch installations plausibly affected (ArubaOS-CX is HPE's current OS across its widely deployed Aruba CX switch families); the subset with APIs… — Aruba is a top-tier enterprise LAN switching vendor and ArubaOS-CX is its current campus/data-center switch operating system, implying a global installed base in the hundreds of thousands of units or more, though only devices with the API…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.