Every CVE whose affected-product data names Hpe Arubaos-cx, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (57)
CVE-2026-23813 — CVSS 9.8 (critical): A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an…
CVE-2026-73749 — CVSS 9.8 (critical): Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote…
CVE-2026-73782 — CVSS 8.8 (high): A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution…
CVE-2021-41001 — CVSS 8.8 (high): An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch…
CVE-2023-3718 — CVSS 8.8 (high): An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability…
CVE-2026-73751 — CVSS 8.8 (high): An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary…
CVE-2026-73750 — CVSS 8.8 (high): Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote…
CVE-2026-23814 — CVSS 8.8 (high): A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to…
CVE-2026-73753 — CVSS 8.8 (high): Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a…
CVE-2021-41000 — CVSS 8.8 (high): Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch…
CVE-2026-44880 — CVSS 8.8 (high): A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could…
CVE-2026-73752 — CVSS 8.8 (high): An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability…
CVE-2026-73781 — CVSS 8.4 (high): A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site…
CVE-2026-73780 — CVSS 8.3 (high): A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery…
CVE-2026-73779 — CVSS 8.2 (high): Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote…
CVE-2026-73778 — CVSS 8.1 (high): A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote…
CVE-2021-41002 — CVSS 8.1 (high): Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch…
CVE-2026-73777 — CVSS 8.1 (high): Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to…
CVE-2026-73776 — CVSS 7.9 (high): A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an…
CVE-2025-37155 — CVSS 7.8 (high): A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated…
CVE-2026-73775 — CVSS 7.7 (high): Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive…
CVE-2026-73774 — CVSS 7.6 (high): A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of…
CVE-2002-20001 — CVSS 7.5 (high): The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not…
CVE-2026-73771 — CVSS 7.5 (high): An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An…
CVE-2026-73773 — CVSS 7.5 (high): An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this…
CVE-2026-73768 — CVSS 7.3 (high): A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful…
CVE-2026-73770 — CVSS 7.3 (high): An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor…
CVE-2026-23816 — CVSS 7.2 (high): A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands…
CVE-2026-23815 — CVSS 7.2 (high): A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to…
CVE-2026-73766 — CVSS 7.2 (high): Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges…
CVE-2026-63453 — CVSS 7.2 (high): Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow…
CVE-2023-1168 — CVSS 7.2 (high): An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this…
CVE-2026-73767 — CVSS 7.2 (high): Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these…
CVE-2026-73765 — CVSS 7.2 (high): Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an…
CVE-2026-63454 — CVSS 7.2 (high): An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy…
CVE-2026-73764 — CVSS 7.1 (high): Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote…
CVE-2026-73763 — CVSS 7.1 (high): A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands…
CVE-2025-37156 — CVSS 6.8 (medium): A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could…
CVE-2025-37157 — CVSS 6.7 (medium): A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote…
CVE-2025-37158 — CVSS 6.7 (medium): A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote…
CVE-2026-73762 — CVSS 6.6 (medium): A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls…
CVE-2026-73761 — CVSS 6.5 (medium): An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information…
CVE-2026-23817 — CVSS 6.5 (medium): A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users…
CVE-2026-73758 — CVSS 6.5 (medium): A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low…
CVE-2026-73759 — CVSS 6.5 (medium): Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending…
CVE-2026-73760 — CVSS 6.5 (medium): An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read…
CVE-2026-73772 — CVSS 6.5 (medium): Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition…
CVE-2026-73757 — CVSS 6.4 (medium): A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side…
CVE-2021-41003 — CVSS 6.1 (medium): Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series…
CVE-2026-73756 — CVSS 5.9 (medium): A vulnerability in an API endpoint of AOS-CX could allow a remote unauthenticated attacker to obtain sensitive information via a…
CVE-2025-37159 — CVSS 5.8 (medium): A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker…
CVE-2026-73755 — CVSS 5.7 (medium): A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated…
CVE-2025-37160 — CVSS 5.3 (medium): A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low…
CVE-2026-73754 — CVSS 5.3 (medium): Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user…
CVE-2026-73783 — CVSS 4.9 (medium): Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to…
CVE-2024-54010 — CVSS 3.4 (low): A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated…
CVE-2025-25040 — CVSS 3.3 (low): A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch…