Junglewise Threat Intelligence

CVE-2026-73761: Hewlett Packard Enterprise AOS-CX out-of-bounds read

CVE-2026-73761 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Vendors: Hewlett Packard Enterprise.

Executive brief

AOS-CX is a network operating system used in Hewlett Packard Enterprise switches and routers. An out-of-bounds read vulnerability in the underlying OS allows an unauthenticated attacker to send a specially crafted packet and disclose sensitive system information, potentially exposing configuration details or other confidential data that could aid further attacks.

Technical details

The vulnerability is an out-of-bounds read in the underlying operating system of AOS-CX, triggered by receipt of a specially crafted network packet. No authentication is required to exploit this vulnerability, as the attack is network-based. Successful exploitation allows an attacker to read sensitive memory contents from the operating system, potentially disclosing configuration details, cryptographic material, or other confidential information. The vulnerability is assigned CVE-2026-73761 with a CVSS v3 score of 6.5 (medium severity), indicating a moderate risk to confidentiality without direct impact on integrity or availability.

Affected products

  • Hewlett Packard Enterprise AOS-CX <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References