CVE-2026-73773
massUnauthenticated DoS in the API of HPE ArubaOS-CX Switches
CVE-2026-73773 is an unauthenticated denial-of-service vulnerability in the API endpoint of HPE's ArubaOS-CX network operating system, which runs on HPE Aruba's CX-series campus and data center switches. An attacker with network reachability to the switch's API can send requests that disrupt the normal operation of the affected service, with no privileges or user interaction required (CVSS 3.1: AV:N/AC:L/PR:N/UI:N) and no confidentiality or integrity impact; the CWE-400 classification suggests resource-exhaustion behavior. Organizations running ArubaOS-CX with the API interface enabled are potentially affected; the provided data does not specify affected version ranges, so defenders should confirm scope against HPE's advisory. Exploitation has not been observed: the flaw is not in CISA's KEV catalog, EPSS assigns a low ~0.3% probability of exploitation within 30 days, and no public proof-of-concept is known.
What to do: Inventory ArubaOS-CX switches in your estate, review HPE's advisory for the list of affected and fixed releases, and upgrade to the fixed firmware from the HPE support portal during the next maintenance window. Until patched, restrict reachability of the switch API (management interface) to trusted management networks using ACLs or out-of-band management, and disable the API on devices that do not use it. Given low EPSS and no known public PoC or in-the-wild exploitation, routine prioritized patching is proportionate.
| HPE ArubaOS-CX | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.