Sceawere

Vulnerability Detail

CVE-2026-73770UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AOS-CX Authenticated Arbitrary File Write

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
4h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
AOS-CX
Attack Type
N/A
Vector String
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-01T21:18:43.720Z",
  "pubdate": "2026-09-01T21:18:43.720Z",
  "executiveSummary": "An authenticated arbitrary file write vulnerability has been identified within AOS-CX. This security flaw enables a malicious actor, who has already gained authenticated access to the system, to potentially achieve remote code execution (RCE) with elevated privileges on the underlying operating system.\nThe vulnerability is characterized by a failure to properly sanitize user-controlled input when handling file operations. Successful exploitation requires specific, prerequisite conditions—specifically, an external action performed by another user—making the exploit path non-deterministic for the attacker. If these conditions are met, the attacker can leverage the file write primitive to modify critical system files or inject malicious configuration files.\nThe risk implication is critical, as it allows for full system compromise, persistent backdoor installation, and unauthorized access to privileged OS functions. The vulnerability affects AOS-CX deployments, and exploitation is strictly limited to authenticated users, necessitating a focus on internal network security and robust access control measures to mitigate the threat of compromised insider accounts.",
  "technicalDetails": "The vulnerability resides within the AOS-CX management framework, specifically involving how the system processes file write requests submitted via an authenticated session. The root cause is identified as an insufficient validation mechanism during the handling of file system paths or content, which permits an attacker to perform write operations to unauthorized locations within the underlying OS file system.\nExploitation follows a specific, multi-stage workflow. Initially, the attacker must have established an authenticated session with the AOS-CX device. The attack is not directly triggerable through a simple request but instead relies on a dependency involving a required action by another user. This suggests the vulnerability likely involves an asynchronous event or a race condition where the attacker injects malicious input that is subsequently processed or executed by a privileged system process following the second user's interaction.\nDuring the attack flow, the malicious actor manipulates parameters associated with a file write function. By bypassing path traversal or input validation filters, the attacker can overwrite sensitive configuration files, binary files, or script files stored on the underlying Linux-based operating system. When the privileged component or the secondary user performs an action that triggers the execution or loading of these manipulated files, the payload is executed with the privileges of the system process responsible for the write action.\nThe impact of this exploit is severe, as it facilitates arbitrary command execution at a privileged level. Because AOS-CX operates on an underlying OS that manages core networking services, post-exploitation behavior may include the installation of persistent malicious implants, the modification of system-wide security policies, or the exfiltration of sensitive device data. The vulnerability is constrained by the need for initial authentication; however, once inside the management plane, the lack of effective file system sandboxing or integrity verification for critical files allows the attacker to escalate privileges and gain full control over the appliance. The interaction dependency acts as an operational barrier, yet it does not eliminate the catastrophic security implications if an attacker successfully orchestrates the required conditions."
}
CVE-2026-73770: AOS-CX Authenticated Arbitrary File Write (HIGH Severity, CVSS: 7.3) - Sceawere