Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73779— Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CX

Quick assessment

Affected
Hewlett Packard Enterprise (HPE) AOS-CX
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Hewlett Packard Enterprise AOS-CX是美国Hewlett Packard Enterprise公司的一款网络交换机操作系统。 Hewlett Packard Enterprise AOS-CX 10.18.0000版本至10.18.0001版本、10.17.0000版本至10.17.1021版本、10.16.0000版本至10.16.1051版本、10.13.0000版本至10.13.1180版本和10.10.0000版本至10.10.1180版本存在安全漏洞,该漏洞源于操作

CVSS 8.2 · High EPSS 0.17% · P7

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 5

VendorProduct Version RangeStatus
Hewlett Packard Enterprise (HPE) AOS-CX 10.18.0000≤ 10.18.0001 affected
10.17.0000≤ 10.17.1021 affected
10.16.0000≤ 10.16.1051 affected
10.13.0000≤ 10.13.1180 affected
10.10.0000≤ 10.10.1180 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73779

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CX
Source: CVE Program / CVE List V5
Vulnerability Description
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Hewlett Packard Enterprise AOS-CX 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Hewlett Packard Enterprise AOS-CX是美国Hewlett Packard Enterprise公司的一款网络交换机操作系统。 Hewlett Packard Enterprise AOS-CX 10.18.0000版本至10.18.0001版本、10.17.0000版本至10.17.1021版本、10.16.0000版本至10.16.1051版本、10.13.0000版本至10.13.1180版本和10.10.0000版本至10.10.1180版本存在安全漏洞,该漏洞源于操作
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Hewlett Packard Enterprise (HPE) AOS-CX 10.18.0000 ~ 10.18.0001 -

II. Public POCs for CVE-2026-73779

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73779

登录查看更多情报信息。

Same Patch Batch · Hewlett Packard Enterprise (HPE) · 2026-09-01 · 86 CVEs total

CVE-2026-76658 10.0 CRITICAL Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon
CVE-2026-76657 10.0 CRITICAL Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access
CVE-2026-73749 9.8 CRITICAL Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
CVE-2026-19766 9.6 CRITICAL Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Net
CVE-2026-73701 9.0 CRITICAL Unauthenticated Remote Code Execution in HPE Networking Fabric Composer
CVE-2026-73700 9.0 CRITICAL Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Com
CVE-2026-73702 8.8 HIGH Authenticated Privilege Escalation Vulnerability in the API of HPE Networking Fabric Compo
CVE-2026-73703 8.8 HIGH Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric C
CVE-2026-73704 8.8 HIGH Authenticated Command Injection Leading to Administrative Access in HPE Networking Fabric
CVE-2026-73705 8.8 HIGH Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Networking Fabric
CVE-2026-73782 8.8 HIGH Unauthenticated Format String Vulnerability leads to Remote Code Execution in AOS-CX
CVE-2026-73750 8.8 HIGH Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Cod
CVE-2026-73751 8.8 HIGH Authenticated Remote Command Injection in AOS-CX Web-based Management Interface
CVE-2026-73752 8.8 HIGH Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-C
CVE-2026-73753 8.8 HIGH Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface
CVE-2026-73706 8.6 HIGH Authentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure an
CVE-2026-73707 8.5 HIGH Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Comp
CVE-2026-73781 8.4 HIGH Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-Based Manageme
CVE-2026-73709 8.3 HIGH Unauthenticated Remote Code Execution during HPE Networking Fabric Composer Installation P
CVE-2026-73708 8.3 HIGH Fault in Business Logic allows Authenticated Sensitive Information Disclosure in HPE Netwo

Showing top 20 of 86 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-73779

No comments yet


Leave a comment