VendorsHPEarubaos-cxall versions
Vulnerabilities

HPE Arubaos-cx

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2026-73749
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Published 2026-09-01 · Analyzed
9.8EPSS 0.008
CVE-2026-23813
Authentication Bypass in Web Interface allows Unauthenticated Admin Password Reset
Published 2026-03-11 · Analyzed
9.8EPSS 0.007
CVE-2026-73778
Credential Manager Vulnerability Allows Unauthorized Administrative Access
Published 2026-09-01 · Analyzed
9.8EPSS 0.005
CVE-2021-41001
An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.09.xxxx: 10.09.0002 and below. Aruba has released upgrades for Aruba AOS-CX devices that address this security vulnerability.
Published 2022-03-02 · Modified
9.0EPSS 0.027
CVE-2021-41000
Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below. Aruba has released upgrades for Aruba AOS-CX devices that address these security vulnerabilities.
Published 2022-03-02 · Modified
9.0EPSS 0.026
CVE-2023-3718
Authenticated Command Injection Vulnerability in AOS-CX Command Line Interface
Published 2023-08-01 · Modified
8.8EPSS 0.016
CVE-2026-23816
Authenticated Command Injection found in admin AOS-CX CLI command
Published 2026-03-11 · Analyzed
8.8EPSS 0.012
CVE-2023-1168
Authenticated Remote Code Execution in Aruba CX Switches
Published 2023-03-21 · Modified
8.8EPSS 0.011
CVE-2026-73750
Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution
Published 2026-09-01 · Analyzed
8.8EPSS 0.008
CVE-2026-44880
Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Published 2026-07-21 · Analyzed
8.8EPSS 0.008
CVE-2026-73751
Authenticated Remote Command Injection in AOS-CX Web-based Management Interface
Published 2026-09-01 · Analyzed
8.8EPSS 0.007
CVE-2026-73753
Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface
Published 2026-09-01 · Analyzed
8.8EPSS 0.007
CVE-2025-37157
Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX
Published 2025-11-18 · Analyzed
8.8EPSS 0.007
CVE-2025-37158
Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX
Published 2025-11-18 · Analyzed
8.8EPSS 0.007
CVE-2026-23814
Authenticated Command Injection found in AOS-CX CLI Command
Published 2026-03-11 · Analyzed
8.8EPSS 0.006
CVE-2026-73763
Unauthenticated Remote Command Execution in Management Component
Published 2026-09-01 · Analyzed
8.8EPSS 0.005
CVE-2026-73752
Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-CX
Published 2026-09-01 · Analyzed
8.8EPSS 0.005
CVE-2026-73782
Unauthenticated Format String Vulnerability leads to Remote Code Execution in AOS-CX
Published 2026-09-01 · Analyzed
8.8EPSS 0.004
CVE-2021-41002
Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.09.xxxx: 10.09.0002 and below. Aruba has released upgrades for Aruba AOS-CX devices that address these security vulnerabilities.
Published 2022-03-02 · Modified
8.5EPSS 0.010
CVE-2026-73781
Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-Based Management Interface
Published 2026-09-01 · Analyzed
8.4EPSS 0.005
CVE-2026-73780
Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessions in AOS-CX
Published 2026-09-01 · Analyzed
8.3EPSS 0.002
CVE-2026-73779
Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CX
Published 2026-09-01 · Analyzed
8.2EPSS 0.002
CVE-2026-73777
Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API Endpoint
Published 2026-09-01 · Analyzed
8.1EPSS 0.005
CVE-2026-73776
Authenticated Signature Verification Bypass Leading to Arbitrary Code Execution in AOS-CX
Published 2026-09-01 · Analyzed
7.9EPSS 0.001
CVE-2025-37155
Authenticated Privilege Escalation Allows Unauthorized Access in Network Management Interface
Published 2025-11-18 · Analyzed
7.8EPSS 0.001
CVE-2026-73775
Authenticated Sensitive Information Disclosure Vulnerabilities in AOS-CX
Published 2026-09-01 · Analyzed
7.7EPSS 0.005
CVE-2026-73774
Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information Disclosure in AOS-CX
Published 2026-09-01 · Analyzed
7.6EPSS 0.003
CVE-2002-20001
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
Published 2021-11-11 · Analyzed
7.5EPSS 0.246
CVE-2026-73771
Improper Authentication Handling in AOS-CX Management Interface and API
Published 2026-09-01 · Analyzed
7.5EPSS 0.005
CVE-2026-73773
Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CX
Published 2026-09-01 · Analyzed
7.5EPSS 0.005
CVE-2025-37159
Authenticated Session Hijacking Allows Unauthorized Access in Network Switching Software
Published 2025-11-18 · Analyzed
7.3EPSS 0.003
CVE-2026-73770
Authenticated Arbitrary File Write Vulnerability Leading to Remote Code Execution in AOS-CX
Published 2026-09-01 · Analyzed
7.3EPSS 0.002
CVE-2026-73768
Local Privilege Escalation in AOS-CX Command Line Interface
Published 2026-09-01 · Analyzed
7.3EPSS 0.002
CVE-2026-73767
Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface
Published 2026-09-01 · Analyzed
7.2EPSS 0.017
CVE-2026-73766
Authenticated Command Injection Vulnerabilities in the API Endpoint of AOS-CX
Published 2026-09-01 · Analyzed
7.2EPSS 0.015
CVE-2026-23815
Authenticated Command Injection found in AOS-CX Administrative CLI Command
Published 2026-03-11 · Analyzed
7.2EPSS 0.009
CVE-2026-73765
Authenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in AOS-CX
Published 2026-09-01 · Analyzed
7.2EPSS 0.009
CVE-2026-63454
Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX
Published 2026-07-21 · Analyzed
7.2EPSS 0.009
CVE-2026-63453
Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Published 2026-07-21 · Analyzed
7.2EPSS 0.006
CVE-2026-73764
Authentication Bypass Vulnerabilities Leading to Unauthorized Modification and Service Disruption in AOS-CX
Published 2026-09-01 · Analyzed
7.1EPSS 0.003
1 / 2Next →