Junglewise Threat Intelligence

CVE-2026-73756: Arista AOS-CX API information disclosure via man-in-the-middle

CVE-2026-73756 · Severity: medium · CVSS 5.9 · Published 2026-09-01

Vendors: Arista.

Executive brief

Arista AOS-CX is a network operating system used in switches and routing equipment. A vulnerability in an API endpoint allows remote attackers without authentication to intercept and read sensitive system information through a man-in-the-middle attack, potentially compromising the security posture of the affected network infrastructure.

Technical details

The vulnerability exists in an API endpoint within Arista AOS-CX that fails to enforce encryption or integrity protection on sensitive data exchanges. An attacker positioned on the network path between a client and the affected AOS-CX device can perform a man-in-the-middle attack to intercept and read API responses without requiring authentication. The attack requires network adjacency to the communication path but allows disclosure of sensitive information that could enable further attacks against the system. Details on affected versions and patching are available from HPE/Arista support documentation.

Affected products

  • Arista AOS-CX

Timeline

  • 2026-09-01: disclosed

References