Hewlett Packard EnterpriseCVE-2026-73771
Hewlett Packard Enterprise AOS-CX: improper authentication
High7.5CVE-2026-73771 · Published Sep 1, 2026 · updated Sep 4, 2026
An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| AOS-CX Product | >= 10.18.0000, <= 10.18.0001 | No fix yet |
| >= 10.17.0000, <= 10.17.1021 | No fix yet | |
| >= 10.16.0000, <= 10.16.1051 | No fix yet | |
| >= 10.13.0000, <= 10.13.1180 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-287
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 1 | Hewlett Packard Enterprise AOS-CX: remote code execution | High8.8 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: denial of service | Medium4.9 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: denial of service | High7.5 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: buffer overflow | High7.6 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: information disclosure | High7.7 | No fix yet |
| Sep 1 | Hewlett Packard Enterprise AOS-CX: code execution | High7.9 | No fix yet |