Description
An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system.
Published: 2026-09-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An operating system flaw in AOS-CX allows an attacker to trigger an out‑of‑bounds read by sending a specially crafted packet. The vulnerability is unauthenticated, meaning that any host on the network can send the payload and receive sensitive data from the underlying OS. The effect is the exposure of confidential system information that could aid further attacks. The weakness maps to CWE‑125 (Out‑of‑Bounds Read) and CWE‑200 (Information Exposure).

Affected Systems

Hewlett Packard Enterprise’s AOS‑CX platform is impacted. No specific version information is provided, so the issue may exist across all current releases until an official patch is released.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium‑severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, meaning that active exploitation data is limited. Because the flaw is unauthenticated, an attacker only needs to contact the device over the network to trigger the read; thus the attack surface is broad and the barrier to exploitation is low.

Generated by OpenCVE AI on September 2, 2026 at 01:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available firmware or OS update from Hewlett Packard Enterprise that addresses the out‑of‑bounds read in AOS‑CX.
  • Configure network segmentation or firewall policies to limit inbound traffic to the AOS‑CX management interfaces to trusted hosts only.
  • Implement network monitoring to detect anomalous packets targeting the AOS‑CX services that could indicate attempts to exploit the read flaw.

Generated by OpenCVE AI on September 2, 2026 at 01:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-200

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system.
Title Unauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclosure in AOS-CX
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:28:19.500Z

Reserved: 2026-08-13T16:38:49.644Z

Link: CVE-2026-73761

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T21:18:42.850

Modified: 2026-09-01T21:18:42.850

Link: CVE-2026-73761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:00:13Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor