Sceawere

Vulnerability Detail

CVE-2026-73761UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AOS-CX Out-of-Bounds Read Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
AOS-CX
Attack Type
N/A
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive information from the underlying operating system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-01T21:18:42.850Z",
  "pubdate": "2026-09-01T21:18:42.850Z",
  "executiveSummary": "A critical out-of-bounds read vulnerability has been identified within the AOS-CX operating system, posing a significant risk of unauthorized information disclosure.\nThe vulnerability allows an unauthenticated, remote attacker to trigger an out-of-bounds read condition by submitting a specially crafted network packet to the device.\nSuccessful exploitation grants the attacker the ability to extract sensitive memory contents from the underlying operating system, potentially exposing cryptographic keys, system configurations, or sensitive process data.\nThis vulnerability resides in the core OS stack, and because it can be triggered without authentication, the risk level is high. Attackers do not require prior access to the system to initiate the attack, as the payload is delivered via standard network protocol interactions.\nThe primary risk implication is a breach of confidentiality, which may facilitate further exploitation or compromise the integrity of the broader network infrastructure managed by the affected AOS-CX device.",
  "technicalDetails": "The vulnerability is characterized as an out-of-bounds (OOB) read condition originating from improper input validation within the AOS-CX network stack processing routines.\nThe root cause involves a failure to adequately sanitize or verify the length and boundary parameters of incoming network packets before accessing memory buffers. When a specially crafted packet containing malicious header or payload metadata is processed, the system fails to constrain memory access to the allocated buffer range.\nThe attack flow begins with an attacker transmitting a maliciously structured packet directed at the affected network service. Upon reception, the vulnerable parsing function reads the attacker-supplied length or offset values directly from the packet headers.\nIf these values exceed the boundaries of the designated memory buffer, the system attempts to access adjacent memory segments. This OOB read allows the attacker to read arbitrary data residing beyond the legitimate buffer, which may include sensitive internal OS kernel memory or user-space memory belonging to other processes.\nSince the exploitation process does not rely on memory corruption for arbitrary code execution but rather data exfiltration, the exploit remains stealthy. The attacker iteratively crafts packets to disclose specific segments of system memory, potentially reconstructing sensitive data structures.\nNo authentication or elevated privileges are required to reach the vulnerable component. The network exposure is broad, as the vulnerability affects the baseline OS packet processing mechanism, making any interface capable of receiving such traffic a potential vector for exploitation.\nPost-exploitation, the impact is strictly limited to information disclosure. The confidentiality of the AOS-CX device is severely compromised, providing an attacker with foundational intelligence to bypass secondary security controls, potentially leading to a complete system compromise or lateral movement within the network segment."
}
CVE-2026-73761: AOS-CX Out-of-Bounds Read Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere