VYPR

AOS-CX

by HPE

CVEs (29)

  • CVE-2026-73749CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could…

  • CVE-2026-73752HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.

  • CVE-2026-44880HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

  • CVE-2026-23814HigMar 11, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

  • CVE-2026-73781HigSep 1, 2026
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script…

  • CVE-2026-73776HigSep 1, 2026
    risk 0.51cvss 7.9epss 0.00

    A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code on the underlying operating system, when certain…

  • CVE-2026-73775HigSep 1, 2026
    risk 0.50cvss 7.7epss 0.00

    Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network…

  • CVE-2026-73774HigSep 1, 2026
    risk 0.49cvss 7.6epss 0.00

    A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in…

  • CVE-2026-73771HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system…

  • CVE-2026-73770HigSep 1, 2026
    risk 0.47cvss 7.3epss 0.00

    An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary…

  • CVE-2026-73768HigSep 1, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges.

  • CVE-2026-73767HigSep 1, 2026
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2026-73766HigSep 1, 2026
    risk 0.47cvss 7.2epss 0.01

    Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the…

  • CVE-2026-73765HigSep 1, 2026
    risk 0.47cvss 7.2epss 0.01

    Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.

  • CVE-2026-63454HigJul 21, 2026
    risk 0.47cvss 7.2epss 0.01

    An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote…

  • CVE-2026-63453HigJul 21, 2026
    risk 0.47cvss 7.2epss 0.01

    Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

  • CVE-2026-73762MedSep 1, 2026
    risk 0.43cvss 6.6epss 0.00

    A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control…

  • CVE-2026-73772MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of…

  • CVE-2026-73761MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive…

  • CVE-2026-73760MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to…

Page 1 of 2