๐Ÿ” CVE Alert

CVE-2026-73774

HIGH 7.6

Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information Disclosure in AOS-CX

CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th

A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in limited disclosure or modification of information and disruption of the affected system.

Vendor hewlett packard enterprise (hpe)
Product aos-cx
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for hewlett packard enterprise (hpe) aos-cx

Be the first to know when new high vulnerabilities affecting hewlett packard enterprise (hpe) aos-cx are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High

Affected Versions

Hewlett Packard Enterprise (HPE) / AOS-CX
10.18.0000 โ‰ค 10.18.0001 10.17.0000 โ‰ค 10.17.1021 10.16.0000 โ‰ค 10.16.1051 10.13.0000 โ‰ค 10.13.1180 10.10.0000 โ‰ค 10.10.1180

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.hpe.com: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

Credits

๐Ÿ” This vulnerability was discovered by internal security research at HPE Networking.