CVE-2026-73783
Analyzed
Analyzed - Analysis Complete
Buffer Overflow in HPE ArubaOS-CX API
Vulnerability report for CVE-2026-73783, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-01
Last updated on: 2026-09-04
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hpe | arubaos-cx | From 10.13.0000 (inc) to 10.13.1180 (inc) |
| hpe | arubaos-cx | to 10.10.1180 (inc) |
| hpe | arubaos-cx | From 10.16.0000 (inc) to 10.16.1051 (inc) |
| hpe | arubaos-cx | From 10.17.0000 (inc) to 10.17.1021 (inc) |
| hpe | arubaos-cx | 10.18.0001 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-121 | A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function). |