Junglewise Threat Intelligence

CVE-2026-73783: HPE Arista AOS-CX stack overflow in API endpoint

CVE-2026-73783 · Severity: medium · CVSS 4.9 · Published 2026-09-01

Vendors: Hpe.

Executive brief

AOS-CX is a network operating system used to manage and control data center and enterprise switches. A stack overflow vulnerability in its API endpoint could allow an authenticated attacker to crash the system, causing network outages and disrupting business operations.

Technical details

A stack overflow vulnerability exists in an API endpoint of AOS-CX that can be triggered by an authenticated malicious actor. The vulnerability allows an attacker to overflow the stack memory by sending specially crafted input to the affected API endpoint. Successful exploitation leads to a denial-of-service condition, potentially causing the affected system to become unavailable. Authentication is required to exploit this vulnerability, limiting the attack surface to authenticated users or those with valid credentials. The vulnerability affects AOS-CX and patches or workarounds may be available from HPE support.

Affected products

  • HPE AOS-CX

Timeline

  • 2026-09-01: disclosed

References