Junglewise Threat Intelligence

CVE-2026-73773: HPE AOS-CX API endpoint denial-of-service

CVE-2026-73773 · Severity: high · CVSS 7.5 · Published 2026-09-01

Vendors: Hpe.

Executive brief

AOS-CX is HPE's advanced networking operating system used in switches and routers to manage enterprise networks. An unauthenticated remote attacker can trigger a denial-of-service condition via the API endpoint, disrupting network connectivity and availability for all devices and services depending on the affected switch.

Technical details

This vulnerability is an unauthenticated denial-of-service flaw in the API endpoint of AOS-CX. The attack vector is network-based and requires no authentication or credentials. An attacker can send specially crafted requests to the API endpoint to exhaust resources or crash the service, preventing legitimate operations. The vulnerability allows interruption of normal service operation on the affected device. Patches are available from HPE support.

Affected products

  • HPE AOS-CX

Timeline

  • 2026-09-01: disclosed

References