Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

AOS-CX — Vulnerabilities & Security Advisories 46

All 46 CVE vulnerabilities found in AOS-CX, with AI-generated Chinese analysis, references, and POCs.

This page provides an aggregation of vulnerability data for Aruba AOS-CX, categorized under network operating system weaknesses with a focus on critical and high-severity issues. The collection includes known security flaws affecting the ArubaOS-CX switch operating system, covering advisory disclosures and public vulnerability entries from the past five years. By browsing this resource, users can effectively track vendor security advisories from Aruba, understand the specific characteristics of weakness classes such as buffer overflows or authentication bypasses, and investigate the detailed vulnerability history associated with their specific AOS-CX device versions. The data is structured to help security administrators assess risk exposure and prioritize patching efforts for their network infrastructure. This compilation serves as a reference for identifying past incidents and understanding the evolution of security issues within the AOS-CX ecosystem. It does not offer real-time monitoring but rather historical context to support informed decision-making regarding system maintenance and upgrade strategies. The information presented is derived from public sources and vendor official notes to ensure accuracy and relevance for enterprise IT professionals managing Aruba networking equipment.

Vendor: Hewlett Packard Enterprise (HPE)

CVE ID Title CVSS Severity Published
CVE-2026-73752 Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-CX 8.8 High 2026-09-01
CVE-2026-73751 Authenticated Remote Command Injection in AOS-CX Web-based Management Interface 8.8 High 2026-09-01
CVE-2026-73750 Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution 8.8 High 2026-09-01
CVE-2026-73749 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX 9.8 Critical 2026-09-01
CVE-2026-63454 Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX 7.2 High 2026-07-21
CVE-2026-63453 Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX 7.2 High 2026-07-21
CVE-2026-44880 Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX 8.8 High 2026-07-21
CVE-2026-23817 Unauthenticated Open Redirect allows URL Manipulation in Web Interface 6.5 Medium 2026-03-11
CVE-2026-23816 Authenticated Command Injection found in admin AOS-CX CLI command 7.2 High 2026-03-11
CVE-2026-23815 Authenticated Command Injection found in AOS-CX Administrative CLI Command 7.2 High 2026-03-11
CVE-2026-23814 Authenticated Command Injection found in AOS-CX CLI Command 8.8 High 2026-03-11
CVE-2026-23813 Authentication Bypass in Web Interface allows Unauthenticated Admin Password Reset 9.8 Critical 2026-03-11
CVE-2025-27080 Authenticated Sensitive Information Disclosure exposes Credentials in AOS-CX Command Line Interface 6.0 Medium 2025-03-18
CVE-2025-25042 Authenticated Access Control Vulnerability allows Sensitive Information Disclosure in AOS-CX REST Interface 4.3 Medium 2025-03-18
CVE-2025-25040 Failure to Properly Enforce Port ACLs on CPU generated packets in CX 9300 Switches 3.3 Low 2025-03-18
CVE-2024-54010 Unauthenticated Traffic Handling Flaw Allows Packet Leakage on HPE Aruba Networking CX 10000 series switches 3.4 Low 2025-01-08

All 46 known CVE vulnerabilities affecting AOS-CX with full Chinese analysis, references, and POCs where available.