Description
Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
Published: 2026-09-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated low‑privileged user can run arbitrary operating‑system commands through vulnerable CLI operations, thereby escalating privileges to a privileged user. The flaw permits the attacker to inject any command that the underlying OS would execute, providing complete control over the device and its data. Such a vulnerability can compromise confidentiality, integrity, and availability of the network segment protected by the device.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise AOS‑CX devices. No specific version range is supplied in the current advisory, so all instances of AOS‑CX that expose the vulnerable command‑line interface are potentially impacted. Administrators should consult the vendor documentation to confirm whether their deployment includes the affected operations.

Risk and Exploitability

With a CVSS score of 8.8 the flaw is classified as high severity. The EPSS score is currently unavailable, which limits precise exploitation probability estimates, and the flaw is not listed in the CISA KEV catalog. Attack requires valid credentials for a low‑privileged account on the device, but once authenticated the attacker can execute privileged commands. The lack of a publicly disclosed exploit does not negate the risk, as the vulnerability itself enables local code execution with elevated privileges.

Generated by OpenCVE AI on September 2, 2026 at 01:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s AOS‑CX patch or updated firmware that resolves the command‑line injection flaw.
  • Restrict CLI access by removing or limiting low‑privileged accounts that have the capability to invoke the vulnerable commands.
  • Enable comprehensive logging and a monitoring system to detect unexpected or unauthorized command execution patterns.

Generated by OpenCVE AI on September 2, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.
Title Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:28:07.381Z

Reserved: 2026-08-13T16:38:28.876Z

Link: CVE-2026-73753

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T21:18:41.863

Modified: 2026-09-01T21:18:41.863

Link: CVE-2026-73753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:00:13Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')