Description
Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.
Published: 2026-09-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

AOS‑CX can be brought to a non‑responsive state by an unauthenticated remote actor that sends specially crafted network packets. The vulnerability is triggered without any prior authentication or elevated privileges, and the result is a disruption of device availability; confidentiality and integrity are not directly affected.

Affected Systems

Hewlett Packard Enterprise AOS‑CX devices are impacted. No specific firmware or software version list is provided, so all current releases are considered vulnerable until a vendor‑issued update is available.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate to high risk, and the exploitability is facilitated by remote network traffic with no authentication required. EPSS information is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred from the description as remote packet injection: a malicious actor could target the device from outside the local network by sending crafted packets to the affected protocol to trigger a denial‑of‑service condition.

Generated by OpenCVE AI on September 2, 2026 at 02:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE AOS‑CX patch or firmware update from the official HPE support site.
  • If no patch is available, block or rate‑limit traffic using the affected protocol to mitigate DoS attempts.
  • Consider temporarily disabling the network feature or service that processes the crafted packets until a vendor fix is applied.

Generated by OpenCVE AI on September 2, 2026 at 02:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.
Title Unauthenticated Denial-of-Service Vulnerabilities in AOS-CX
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:28:16.173Z

Reserved: 2026-08-13T16:38:28.877Z

Link: CVE-2026-73759

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T21:18:42.630

Modified: 2026-09-01T21:18:42.630

Link: CVE-2026-73759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:15:12Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer