CVE-2026-73757

Summary

A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host, leading to potential disclosure and limited modification of sensitive information.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)AOS-CX10.18.0000 <= 10.18.0001affected
Hewlett Packard Enterprise (HPE)AOS-CX10.17.0000 <= 10.17.1021affected
Hewlett Packard Enterprise (HPE)AOS-CX10.16.0000 <= 10.16.1051affected
Hewlett Packard Enterprise (HPE)AOS-CX10.13.0000 <= 10.13.1180affected
Hewlett Packard Enterprise (HPE)AOS-CX10.10.0000 <= 10.10.1180affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References