Posting Date: 2026-09-21
【Vulnerability Alert】HPE Aruba Networking AOS-CX has 6 high-risk security vulnerabilities. Please verify and apply the patch as soon as possible
- Subject:【Vulnerability Alert】HPE Aruba Networking AOS-CX has 6 high-risk security vulnerabilities. Please verify and apply the patch as soon as possible
- Description:
- Forwarded from the National Information Security Alert and Analysis Center security message alert NISAC-200-202609-00000014
- Researchers have discovered 6 high-risk security vulnerabilities in HPE Aruba Networking AOS-CX (CVE-2026-73749 through CVE-2026-73753 and CVE-2026-73782). The vulnerability types include Improper Access Control, Command Injection, Path Traversal, OS Command Injection, and Use of Externally-Controlled Format String. The most severe vulnerability allows an unauthenticated remote attacker to execute arbitrary code with elevated privileges by sending crafted packets to the affected service. Please verify and apply the patch as soon as possible.
- Affected Platforms:
- AOS-CX 10.18.0001
- AOS-CX 10.17.1021 and earlier
- AOS-CX 10.16.1051 and earlier
- AOS-CX 10.13.1180 and earlier
- AOS-CX 10.10.1180 and earlier
- Recommended Actions:
- The vendor has released patches or updates for the vulnerabilities. Please follow the official instructions. URL: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US
- References:
Computer and Communication Center
Network System Division