Sceawere

Vulnerability Detail

CVE-2026-73777UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AOS-CX API Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
4h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
AOS-CX
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-09-01T21:18:44.520Z",
  "pubdate": "2026-09-01T21:18:44.520Z",
  "executiveSummary": "A critical security vulnerability has been identified within the API endpoints of AOS-CX switches, potentially allowing unauthenticated remote actors to bypass existing authentication controls. This flaw exposes the management interface of the network device to unauthorized access, effectively negating established security policies.\nThe vulnerability represents a significant risk to the integrity and confidentiality of the switch's administrative plane. By circumventing authentication, an attacker can interact directly with the API, enabling the unauthorized retrieval of system information, configuration modification, or the execution of administrative commands.\nThe affected component is the API subsystem within AOS-CX, which is intended to serve as a secure management interface. Because this vulnerability does not require authentication, the attack surface includes any network segment capable of reaching the switch's management interface. This issue poses a severe threat to the operational stability and security posture of the network, as it allows for persistent, unauthenticated control over network infrastructure hardware.",
  "technicalDetails": "The identified vulnerability resides within the authentication middleware responsible for validating session tokens or credentials during API requests to AOS-CX switches. The root cause pertains to an improper implementation of authorization logic, where specific API endpoints fail to correctly verify the authentication state of an incoming request before processing the requested action.\nUnder normal operating conditions, any interaction with the AOS-CX API requires a valid authentication token obtained through a successful login process. However, due to the flaw in the request validation pipeline, the system allows certain API calls to bypass the authentication check entirely. This suggests a failure in the API framework or the underlying web server configuration to enforce mandatory authentication across all defined URI routes.\nThe attack flow proceeds as follows: 1) An unauthenticated actor sends a specially crafted HTTP request to a targeted API endpoint on the AOS-CX switch. 2) The request lacks the required authorization header or session cookie. 3) The switch's API processor, failing to perform the necessary authentication handshake, erroneously treats the request as legitimate. 4) The requested function is executed within the context of an privileged user or system account, depending on the implementation design of the specific API call.\nBecause this vulnerability is triggered remotely without requiring valid credentials, the network exposure is extensive for any switch with an enabled and reachable API service. The exploitation does not require advanced obfuscation or complex payloads; simply targeting the vulnerable API route is sufficient to elicit a response. Post-exploitation impact is critical, as it may allow for the extraction of sensitive system configurations, modification of switch port states, credential harvesting, or the potential for arbitrary code execution if the API endpoint interfaces with underlying system shells or binary utilities.\nThis vulnerability highlights a critical failure in the access control matrix governing the AOS-CX management stack. As the API serves as a primary interface for automation and orchestration, the ability to bypass authentication renders the entire security model of the management plane ineffective against remote adversaries."
}
CVE-2026-73777: AOS-CX API Authentication Bypass (HIGH Severity, CVSS: 8.1) - Sceawere