Executive brief
AOS-CX is a network operating system used in Hewlett Packard Enterprise switches and routers. An out-of-bounds read vulnerability in the underlying OS allows an unauthenticated attacker to send a specially crafted packet and disclose sensitive system information, potentially exposing configuration details or other confidential data that could aid further attacks.
Technical details
The vulnerability is an out-of-bounds read in the underlying operating system of AOS-CX, triggered by receipt of a specially crafted network packet. No authentication is required to exploit this vulnerability, as the attack is network-based. Successful exploitation allows an attacker to read sensitive memory contents from the operating system, potentially disclosing configuration details, cryptographic material, or other confidential information. The vulnerability is assigned CVE-2026-73761 with a CVSS v3 score of 6.5 (medium severity), indicating a moderate risk to confidentiality without direct impact on integrity or availability.
Affected products
- Hewlett Packard Enterprise AOS-CX <UNKNOWN>
Timeline
- 2026-09-01: disclosed