【Security Vulnerability Alert】HPE Aruba Networking AOS-CX contains 6 high-risk security vulnerabilities. Please confirm and apply patches as soon as possible

 
2026/9/29 ~ 2027/3/29
View Count:49

Forwarded from National Information Security Analysis Center Security Information Alert NISAC-200-202609-00000014

[Content Description]
Researchers have discovered 6 high-risk security vulnerabilities (CVE-2026-73749 to CVE-2026-73753 and CVE-2026-73782) in HPE Aruba Networking AOS-CX, including Improper Access Control, Command Injection, Path Traversal, OS Command Injection and Use of Externally-Controlled Format String. The most severe vulnerabilities may allow unauthenticated remote attackers to send specially crafted packets to affected services and thereby execute arbitrary code with elevated privileges. Please confirm and apply patches as soon as possible.

[Affected Platforms]
AOS-CX version 10.18.0001
AOS-CX versions 10.17.1021 (inclusive) and earlier
AOS-CX versions 10.16.1051 (inclusive) and earlier
AOS-CX versions 10.13.1180 (inclusive) and earlier
AOS-CX versions 10.10.1180 (inclusive) and earlier

[Recommended Measures]
The vendor has released patches or updates for the vulnerabilities. Please refer to the official instructions for handling. The URL is as follows: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-73749
2. https://nvd.nist.gov/vuln/detail/CVE-2026-73750
3. https://nvd.nist.gov/vuln/detail/CVE-2026-73751
4. https://nvd.nist.gov/vuln/detail/CVE-2026-73752
5. https://nvd.nist.gov/vuln/detail/CVE-2026-73753
6. https://nvd.nist.gov/vuln/detail/CVE-2026-73782
7. https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

Files
None
Top↑