CVE-2026-73756

Summary

A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a man-in-the-middle attack. Successful exploitation allows an attacker to retrieve data which could be used to further compromise the confidentiality of the affected system.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)AOS-CX10.18.0000 <= 10.18.0001affected
Hewlett Packard Enterprise (HPE)AOS-CX10.17.0000 <= 10.17.1021affected
Hewlett Packard Enterprise (HPE)AOS-CX10.16.0000 <= 10.16.1051affected
Hewlett Packard Enterprise (HPE)AOS-CX10.13.0000 <= 10.13.1180affected
Hewlett Packard Enterprise (HPE)AOS-CX10.10.0000 <= 10.10.1180affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References