CVE-2026-73759
Received Received - Intake

Denial-of-Service in HPE AOS-CX

Vulnerability report for CVE-2026-73759, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe aos-cx *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in AOS-CX allows an unauthenticated remote attacker to cause a denial-of-service condition by sending specially crafted packets. This disrupts normal operation on affected devices.

Detection Guidance

Detecting this vulnerability requires monitoring network traffic for unusual patterns targeting AOS-CX devices. Check for repeated malformed packets or sudden spikes in traffic directed at network switches. Use packet capture tools like tcpdump or Wireshark to inspect traffic for anomalies. Example command: tcpdump -i any -n 'host <target_IP> and not port 22' -c 1000 -w capture.pcap

Impact Analysis

The impact includes disruption of network services on affected devices, leading to potential downtime and loss of connectivity for users and systems relying on those devices.

Compliance Impact

The vulnerability causes denial-of-service conditions on affected devices, which could disrupt critical services. This may impact compliance with standards requiring availability of systems, such as GDPR's data processing requirements or HIPAA's access controls, by potentially leading to service unavailability.

Mitigation Strategies

Immediately apply patches or updates provided by HPE for AOS-CX. If patches are unavailable, restrict access to affected devices by blocking suspicious traffic at the firewall. Disable unnecessary services and monitor network traffic closely for signs of exploitation. Consider isolating vulnerable devices from critical network segments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73759. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart