CVE-2026-73776
Received Received - Intake

Command Line Interface Signature Verification Bypass in AOS-CX

Vulnerability report for CVE-2026-73776, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Hewlett Packard Enterprise (HPE)

Description

A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code on the underlying operating system, when certain pre-conditions outside of the attackerÒ€ℒs control are met.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe aos-cx *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a signature verification bypass in the command line interface of AOS-CX. It allows an authenticated attacker with admin privileges to execute arbitrary code on the underlying operating system if certain external conditions are met.

Impact Analysis

An attacker could gain control of the system, leading to unauthorized code execution, data breaches, or system compromise. This requires admin access but could result in severe operational disruptions.

Compliance Impact

This vulnerability could lead to unauthorized access or data exposure, violating compliance requirements like GDPR (data protection) or HIPAA (health data security). Organizations may face penalties or legal consequences.

Mitigation Strategies

Apply vendor patches or updates for AOS-CX immediately. Restrict administrative privileges to trusted users only. Monitor command line interface activity for suspicious commands. Ensure signature verification mechanisms are enforced.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73776. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart