Description
A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.
Published: 2026-09-01
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote unauthenticated attacker can intercept traffic between a client and the AOS‑CX management API and retrieve information that was not intended to be exposed. This vulnerability allows the attacker to gain access to sensitive data that may help further compromise the system’s confidentiality. The weakness stems from a lack of authentication and encryption on an exposed API endpoint, making it vulnerable to man‑in‑the‑middle attacks.

Affected Systems

Hewlett Packard Enterprise AOS‑CX is affected. No specific version numbers are provided, so all installations of the product should be evaluated for this exposure.

Risk and Exploitability

The CVSS score of 5.9 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, meaning it has no known active exploit at this time. The most likely attack vector is a remote attacker positioned between the client and the affected system who can intercept and read traffic. Exploitation requires no authentication, but the attacker must be able to observe communication to the vulnerable API endpoint.

Generated by OpenCVE AI on September 2, 2026 at 01:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE AOS‑CX patch or upgrade to a version that secures the management API with proper authentication and encryption.
  • Configure firewall or network segmentation to limit exposure of the AOS‑CX API to trusted networks or VPN connections only.
  • Enforce TLS encryption on all API traffic and disable any unencrypted protocols or ports.
  • Monitor network traffic for signs of MITM activity or unauthorized API access attempts.

Generated by OpenCVE AI on September 2, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.
Title Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API Endpoint
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:28:11.651Z

Reserved: 2026-08-13T16:38:28.877Z

Link: CVE-2026-73756

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T21:18:42.210

Modified: 2026-09-01T21:18:42.210

Link: CVE-2026-73756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor