Junglewise Threat Intelligence

CVE-2026-73772: HPE AOS-CX buffer overflow in underlying service

CVE-2026-73772 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Vendors: Hpe.

Executive brief

HPE AOS-CX is a network operating system used in enterprise switches and routers. A buffer overflow vulnerability in an underlying service could allow an attacker to send specially crafted network packets to cause the device to crash or become unresponsive, disrupting network operations.

Technical details

A buffer overflow vulnerability exists in an underlying service component of HPE AOS-CX. The vulnerability can be triggered remotely by sending specially crafted packets to the affected device without requiring authentication. Successful exploitation results in a denial-of-service condition due to disruption of the underlying operating system. The vulnerability is classified as a medium-severity issue with a CVSS score of 6.5, indicating the service can be disrupted but remote code execution is not possible.

Affected products

  • HPE AOS-CX

Timeline

  • 2026-09-01: disclosed

References