CVE-2026-73771
Received Received - Intake

Authentication Bypass in HPE ArubaOS-CX

Vulnerability report for CVE-2026-73771, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe aos-cx *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication issue in the AOS-CX management interface and API. It may allow improper authentication processing, potentially letting an unauthenticated remote attacker bypass authentication controls or exhaust system resources under specific conditions. Successful exploitation could lead to unauthorized access or denial of service affecting the management interface.

Impact Analysis

The impact includes unauthorized access to the management interface, allowing attackers to take control of the system. It may also cause denial of service, disrupting access to the management interface and potentially affecting network operations.

Compliance Impact

This vulnerability could lead to unauthorized access or denial of service in the management interface, potentially violating data protection requirements under GDPR and HIPAA. Unauthorized access may result in exposure of sensitive data, while denial of service could disrupt critical operations, both of which are compliance risks.

Mitigation Strategies

Apply vendor-supplied patches or updates for AOS-CX management interface. Restrict network access to the management interface using firewalls or access control lists. Monitor system logs for unusual authentication attempts or resource exhaustion patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73771. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart