【資安漏洞預警】HPE Aruba Networking AOS-CX存在6個高風險安全漏洞,請儘速確認並進行修補
【Security Vulnerability Alert】HPE Aruba Networking AOS-CX contains 6 high-risk security vulnerabilities. Please confirm and apply patches as soon as possible

發布單位:圖資處網路系統組
日期範圍:2026/9/29 ~ 2027/3/29
 
發布單位:圖資處網路系統組
日期範圍:2026/9/29 ~ 2027/3/29
行政 行政公告
全體

轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202609-00000014

[內容說明]
研究人員發現HPE Aruba Networking AOS-CX存在6個高風險安全漏洞(CVE-2026-73749至CVE-2026-73753與CVE-2026-73782),類型包含不當存取控制(Improper Access Control)、指令注入(Command Injection)、路徑遍歷(Path Traversal)、作業系統指令注入(OS Command Injection)及使用外部控制之格式化字串(Use of Externally-Controlled Format String)。其中最嚴重之漏洞可使未經身分鑑別之遠端攻擊者,藉由對受影響服務傳送特製封包,進而以較高權限執行任意程式碼,請儘速確認並進行修補。

[影響平台]
AOS-CX 10.18.0001版本
AOS-CX 10.17.1021(含)以前版本
AOS-CX 10.16.1051(含)以前版本
AOS-CX 10.13.1180(含)以前版本
AOS-CX 10.10.1180(含)以前版本

[建議措施]
官方已針對漏洞釋出修補或更新,請參考官方說明進行處置,網址如下: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-73749
2. https://nvd.nist.gov/vuln/detail/CVE-2026-73750
3. https://nvd.nist.gov/vuln/detail/CVE-2026-73751
4. https://nvd.nist.gov/vuln/detail/CVE-2026-73752
5. https://nvd.nist.gov/vuln/detail/CVE-2026-73753
6. https://nvd.nist.gov/vuln/detail/CVE-2026-73782
7. https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

Forwarded from National Information Security Analysis Center Security Information Alert NISAC-200-202609-00000014

[Content Description]
Researchers have discovered 6 high-risk security vulnerabilities (CVE-2026-73749 to CVE-2026-73753 and CVE-2026-73782) in HPE Aruba Networking AOS-CX, including Improper Access Control, Command Injection, Path Traversal, OS Command Injection and Use of Externally-Controlled Format String. The most severe vulnerabilities may allow unauthenticated remote attackers to send specially crafted packets to affected services and thereby execute arbitrary code with elevated privileges. Please confirm and apply patches as soon as possible.

[Affected Platforms]
AOS-CX version 10.18.0001
AOS-CX versions 10.17.1021 (inclusive) and earlier
AOS-CX versions 10.16.1051 (inclusive) and earlier
AOS-CX versions 10.13.1180 (inclusive) and earlier
AOS-CX versions 10.10.1180 (inclusive) and earlier

[Recommended Measures]
The vendor has released patches or updates for the vulnerabilities. Please refer to the official instructions for handling. The URL is as follows: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-73749
2. https://nvd.nist.gov/vuln/detail/CVE-2026-73750
3. https://nvd.nist.gov/vuln/detail/CVE-2026-73751
4. https://nvd.nist.gov/vuln/detail/CVE-2026-73752
5. https://nvd.nist.gov/vuln/detail/CVE-2026-73753
6. https://nvd.nist.gov/vuln/detail/CVE-2026-73782
7. https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
無
Top↑