ZeroHour

CVE-2026-73777

large

Authentication bypass in HPE Aruba AOS-CX switch REST API

CVSS 3.1
8.1 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-73777 describes an improper authentication flaw (CWE-287) in the API endpoint of HPE Aruba Networking AOS-CX switches. A remote, unauthenticated actor with network reachability to the switch's API can trigger the flaw to circumvent existing authentication controls, though the CVSS vector (AV:N/AC:H) indicates exploitation requires somewhat unusual conditions. Successful exploitation would grant an attacker unauthenticated access to the device's management API, with CVSS scoring potential high impact to the confidentiality, integrity, and availability of the switch, for example through unauthorized configuration changes. Any organization running AOS-CX switches whose API is reachable by untrusted actors, typically over management networks and in some deployments from the internet, is potentially affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a 0.3% probability of exploitation within 30 days.

What to do: Check the official HPE security advisory for the fixed AOS-CX firmware version applicable to your switch series and upgrade promptly, since specific affected/fixed versions are not included in the available data. Until patched, restrict access to the switch REST API to trusted management networks (management VLANs/ACLs), disable the REST API where it is not required, and avoid exposing the API directly to the internet. Monitor HPE communications for updated version information and any published mitigations.

Affected
HPE ArubaOS-CX (AOS-CX switch operating system, REST/API endpoint)
Estimated exposure
largetens of thousands of installed AOS-CX switches plausibly affected, with likely far fewer having externally reachable APIs — This is a deployment-pattern-based order-of-magnitude estimate: AOS-CX is HPE Aruba's widely deployed enterprise switching OS across campus and data-center networks, but the vulnerable API is normally reachable only on management networks…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.