VendorsHPEarubaos-cxall versions
Vulnerabilities

HPE Arubaos-cx

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2025-37156
ArubaOS-CX Platform-Level Denial-of-Service Vulnerability
Published 2025-11-18 · Analyzed
6.8EPSS 0.003
CVE-2026-73762
Authorization Bypass in the API Endpoint of AOS-CX Leads to Unauthorized Access
Published 2026-09-01 · Analyzed
6.6EPSS 0.003
CVE-2026-73760
Authenticated Path Traversal Vulnerability Leads to Remote Unauthorized Access to Files in AOS-CX
Published 2026-09-01 · Analyzed
6.5EPSS 0.006
CVE-2026-73758
Authenticated Privilege Escalation Vulnerability via Broken Access Control in AOS-CX
Published 2026-09-01 · Analyzed
6.5EPSS 0.003
CVE-2026-73759
Unauthenticated Denial-of-Service Vulnerabilities in AOS-CX
Published 2026-09-01 · Analyzed
6.5EPSS 0.003
CVE-2026-73772
Unauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX
Published 2026-09-01 · Analyzed
6.5EPSS 0.003
CVE-2026-23817
Unauthenticated Open Redirect allows URL Manipulation in Web Interface
Published 2026-03-11 · Analyzed
6.5EPSS 0.003
CVE-2025-37160
Authenticated Broken Access Control (BAC) in REST API Configuration Service
Published 2025-11-18 · Analyzed
6.5EPSS 0.003
CVE-2026-73761
Unauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclosure in AOS-CX
Published 2026-09-01 · Analyzed
6.5EPSS 0.003
CVE-2026-73757
Authenticated Server-Side Request Forgery (SSRF) Leading to Information Disclosure in AOS-CX
Published 2026-09-01 · Analyzed
6.4EPSS 0.003
CVE-2021-41003
Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.09.xxxx: 10.09.0002 and below. Aruba has released upgrades for Aruba AOS-CX devices that address these security vulnerabilities.
Published 2022-03-02 · Modified
6.1EPSS 0.008
CVE-2026-73756
Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API Endpoint
Published 2026-09-01 · Analyzed
5.9EPSS 0.003
CVE-2026-73755
Privilege Escalation via Unauthorized Access to Sensitive Session Information
Published 2026-09-01 · Analyzed
5.7EPSS 0.003
CVE-2026-73754
Authenticated Denial-of-Service Vulnerabilities in the Command Line Interface of AOS-CX
Published 2026-09-01 · Analyzed
5.3EPSS 0.003
CVE-2026-73783
Authenticated Stack Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX
Published 2026-09-01 · Analyzed
4.9EPSS 0.004
CVE-2024-54010
Unauthenticated Traffic Handling Flaw Allows Packet Leakage on HPE Aruba Networking CX 10000 series switches
Published 2025-01-08 · Analyzed
3.4EPSS 0.002
CVE-2025-25040
Failure to Properly Enforce Port ACLs on CPU generated packets in CX 9300 Switches
Published 2025-03-18 · Analyzed
3.3EPSS 0.001
← Prev2 / 2