VYPR

AOS-CX

by HPE

CVEs (29)

  • CVE-2026-73759MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.

  • CVE-2026-73758MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

  • CVE-2026-73757MedSep 1, 2026
    risk 0.42cvss 6.4epss 0.00

    A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host,…

  • CVE-2025-27080MedMar 18, 2025
    risk 0.39cvss 6.0epss 0.00

    Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to…

  • CVE-2026-73755MedSep 1, 2026
    risk 0.37cvss 5.7epss 0.00

    A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.

  • CVE-2026-73754MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system.

  • CVE-2026-73783MedSep 1, 2026
    risk 0.32cvss 4.9epss 0.00

    Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.

  • CVE-2025-25042MedMar 18, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further…

  • CVE-2025-25040LowMar 18, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is…

Page 2 of 2