VYPR

AOS-CX Switches

by HPE

CVEs (7)

  • CVE-2026-73780HigSep 1, 2026
    risk 0.54cvss 8.3epss 0.00

    A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker…

  • CVE-2026-73779HigSep 1, 2026
    risk 0.53cvss 8.2epss 0.00

    Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive…

  • CVE-2026-73777HigSep 1, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.

  • CVE-2026-23816HigMar 11, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

  • CVE-2026-23815HigMar 11, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

  • CVE-2026-73764HigSep 1, 2026
    risk 0.46cvss 7.1epss 0.00

    Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and…

  • CVE-2026-23817MedMar 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.