Sceawere

Vulnerability Detail

CVE-2026-73755UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AOS-CX API Privilege Escalation

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.7
Creation Date
3h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
AOS-CX
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.7",
  "pubDate": "2026-09-01T21:18:42.090Z",
  "pubdate": "2026-09-01T21:18:42.090Z",
  "executiveSummary": "A privilege escalation vulnerability has been identified within the API interface of AOS-CX, potentially allowing authenticated operators with low-level access to gain unauthorized privileges.\nThe vulnerability allows an attacker to bypass standard access control mechanisms, leading to the exposure of sensitive system information.\nSuccessful exploitation requires the attacker to possess valid low-privilege operator credentials and mandates a specific, required user action to trigger the underlying flaw.\nThis vulnerability poses a significant security risk by enabling lateral movement or information disclosure, effectively undermining the principle of least privilege within the network infrastructure.\nImpacted systems are limited to AOS-CX environments where the vulnerable API endpoint is accessible to users with operator-level permissions.\nWhile the attack is restricted to authenticated users, the potential for unauthorized data exfiltration necessitates prompt security assessment and implementation of recommended hardening measures.",
  "technicalDetails": "The vulnerability resides in the API subsystem of AOS-CX, where improper authorization checks fail to adequately enforce privilege boundaries for authenticated users.\nThe root cause is identified as an insufficient validation of user-supplied requests when interacting with specific API endpoints. Although the system verifies authentication tokens, the subsequent authorization logic fails to restrict the scope of accessible data or functions based on the user's assigned role.\nThe exploitation flow begins with the attacker establishing an authenticated session with low-privilege operator rights. Once authenticated, the attacker must initiate a specific user-driven action or request sequence that triggers the vulnerable API routine.\nThe vulnerability facilitates a bypass of the internal Access Control Lists (ACLs) or role-based access control (RBAC) mechanisms governing the API. By crafting a request that the system incorrectly processes as having higher authority, the attacker can force the system to return sensitive information that is intended only for users with administrative privileges.\nThe attack is characterized by an 'authenticated escalation' profile. Because the API does not sufficiently re-verify the authorization state or the scope of the caller during the transaction, the payload effectively elevates the user's access context for the duration of the malicious request.\nPost-exploitation, an attacker can extract sensitive configuration data, system state information, or other restricted telemetry exposed through the compromised API call. This results in unauthorized disclosure of information that could be leveraged for reconnaissance, aiding in further exploitation of the network infrastructure.\nThe scope is localized to the AOS-CX API endpoint architecture. While the vulnerability is restricted to authenticated users, the necessity for a user-triggered action implies that the flaw resides in a dynamic processing component rather than a static misconfiguration of the endpoint interface."
}
CVE-2026-73755: AOS-CX API Privilege Escalation (MEDIUM Severity, CVSS: 5.7) - Sceawere