Sceawere
Vulnerability Detail
CVE-2026-73764UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AOS-CX Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 4h ago
- Vendor
- Hewlett Packard Enterprise (HPE)
- Product
- AOS-CX
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable unauthorized modification of affected resources and limited disruption of affected services.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-01T21:18:43.180Z",
"pubdate": "2026-09-01T21:18:43.180Z",
"executiveSummary": "A critical authentication bypass vulnerability has been identified within the AOS-CX operating system, allowing unauthenticated remote actors to circumvent established security controls. This flaw poses a significant risk to network infrastructure by enabling unauthorized modification of resources and potential service disruption. The vulnerability affects the core authentication architecture of AOS-CX switches, granting attackers a path to interact with protected system functions without valid credentials. Given that the exploit vector is remote and requires no prior authentication, the risk of exploitation is high for internet-facing or poorly segmented management interfaces. Attackers could leverage this access to perform unauthorized configuration changes, intercept or manipulate traffic, or facilitate denial-of-service conditions against critical network services. This vulnerability emphasizes the necessity of strict management plane protection and the implementation of robust network segmentation for all switch administrative interfaces.",
"technicalDetails": "The vulnerability resides within the authentication and authorization framework of the AOS-CX operating system, specifically affecting the validation logic that governs access to management resources. The root cause pertains to an improper handling of authentication tokens or session validation sequences, which allows an attacker to bypass the security handshake required to verify administrative identity. Under normal operations, the AOS-CX authentication module is responsible for verifying credentials via local databases or external AAA (Authentication, Authorization, and Accounting) servers such as RADIUS or TACACS+.\nExploitation involves the transmission of specially crafted packets to the management interface of the target switch. By manipulating specific headers or exploiting flaws in the session management state machine, an unauthorized remote actor can successfully trick the system into granting an authenticated session context without providing valid credentials. Because the system fails to correctly validate the authentication state during these interactions, the security enforcement mechanism is effectively neutralized.\nThe attack flow follows a structured progression: first, the attacker probes the network-accessible management interface to identify endpoints that trigger authentication processes. Second, the attacker executes the bypass payload, which interacts with the vulnerable session handling component. Upon successful injection, the switch incorrectly initializes a session as a high-privileged user. Once this state is achieved, the attacker interacts directly with the AOS-CX CLI or management APIs to execute unauthorized commands.\nThe potential post-exploitation impact includes the modification of system configurations, such as altering routing tables, disabling security features, or redirecting traffic. Furthermore, the attacker can leverage this unauthorized access to induce resource exhaustion within the switch control plane, resulting in a denial-of-service for connected network services. The vulnerability is characterized by its ability to completely bypass the standard authentication barrier, effectively turning a restricted administrative interface into an exposed entry point. This flaw is independent of the authentication mechanism configured (e.g., local versus remote), indicating a fundamental failure in the session management lifecycle within the affected versions of the AOS-CX firmware. Exposure is primarily limited to the management plane; however, if the management interface is improperly isolated from the production network, the scope of the potential impact increases significantly."
}