ZeroHour

CVE-2026-73775

large

Sensitive Information Exposure via Authenticated API in HPE ArubaOS-CX

CVSS 3.1
7.7 high
EPSS
<1%p19
Published
()
Modified
AI analysis

HPE ArubaOS-CX, the network operating system for Aruba's campus and data-center switch line, contains an information-disclosure flaw (CWE-200) in one of its API endpoints. A remote attacker who already holds a low-privileged account can send requests to the API and retrieve sensitive information the account should not be able to access, with no user interaction required. The retrieved data could be used to gain further access to network services supported by AOS-CX; the CVSS vector indicates high confidentiality impact only, with no integrity or availability impact. Any organization running AOS-CX switches with the API enabled and low-privileged accounts is potentially affected, though specific affected firmware version ranges were not included in the available data. No exploitation has been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a ~0.3% probability of exploitation within 30 days.

What to do: Monitor for and apply the patched AOS-CX firmware release listed in the HPE Aruba advisory for CVE-2026-73775 for your switch model/branch. In the interim, restrict access to the switch REST/API (management ACLs, dedicated management network) and review which low-privileged accounts have API access. Because no in-the-wild exploitation or public PoC is known, patching on a normal maintenance cycle is reasonable, but prioritize switches with exposed or broadly reachable management interfaces.

Affected
HPE ArubaOS-CX
Estimated exposure
largeplausibly on the order of 100k–1M AOS-CX switch deployments/users worldwide (estimate); very few devices are likely internet-exposed since these are typically… — ArubaOS-CX is the standard OS across HPE Aruba's current campus and data-center switch families sold to tens of thousands of enterprise networks, implying an installed base in the hundreds of thousands of devices, though no public scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by AOS-CX.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.