Hewlett Packard EnterpriseCVE-2026-73750
Hewlett Packard Enterprise AOS-CX: denial of service
High8.8CVE-2026-73750 · Published Sep 1, 2026 · updated Sep 22, 2026
Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| AOS-CX Product | >= 10.18.0000, <= 10.18.0001 | No fix yet |
| >= 10.17.0000, <= 10.17.1021 | No fix yet | |
| >= 10.16.0000, <= 10.16.1051 | No fix yet | |
| >= 10.13.0000, <= 10.13.1180 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-284
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 1 | Hewlett Packard Enterprise AOS-CX: remote code execution | High8.8 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: denial of service | Medium4.9 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: denial of service | High7.5 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: buffer overflow | High7.6 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: information disclosure | High7.7 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: code execution | High7.9 | No fix yet |