CVE-2026-73772
Received Received - Intake

Buffer Overflow in HPE ArubaOS-CX Leads to DoS

Vulnerability report for CVE-2026-73772, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of normal operation of the underlying operating system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe aos-cx *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow in an underlying service of AOS-CX. It allows unauthenticated attackers to cause a denial-of-service by sending specially crafted packets to the affected device. Exploitation disrupts normal operation of the underlying operating system.

Detection Guidance

Detecting this vulnerability requires monitoring for unusual network traffic or service disruptions targeting AOS-CX devices. Check for repeated crashes or unresponsive services on affected systems. Use network monitoring tools to identify malformed packets sent to the device.

Impact Analysis

The impact includes potential disruption of network services if the affected AOS-CX device is used in your infrastructure. This could lead to downtime or loss of connectivity for systems relying on the device.

Compliance Impact

The vulnerability causes a denial-of-service condition via buffer overflow, disrupting normal operation. This could impact compliance by failing to maintain availability of critical systems, which may violate requirements in GDPR (data processing integrity) and HIPAA (system availability for protected health information).

Mitigation Strategies

Apply vendor patches or updates for AOS-CX immediately. Isolate affected devices from untrusted networks. Implement strict access controls to limit exposure. Monitor for signs of exploitation and disable vulnerable services if patches are unavailable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73772. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart