Sceawere
Vulnerability Detail
CVE-2026-73779UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AOS-CX Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- Hewlett Packard Enterprise (HPE)
- Product
- AOS-CX
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-09-01T21:18:44.737Z",
"pubdate": "2026-09-01T21:18:44.737Z",
"executiveSummary": "A critical security vulnerability has been identified within the operating system of AOS-CX switches, specifically involving the authentication mechanisms governing remote access.\nThis vulnerability is classified as an authentication bypass, which allows an unauthenticated remote threat actor to circumvent established security controls without providing valid credentials.\nThe successful exploitation of this flaw grants unauthorized actors access to the switch management interface, posing a severe risk to system integrity and the confidentiality of sensitive network configurations.\nThe vulnerability affects the core OS of AOS-CX switches and necessitates immediate attention due to the ease with which remote attackers can interact with the device infrastructure.\nThere are no requirements for prior authentication, and exploitation requires only network reachability to the management interface of the target system.\nThe risk implication is extreme, as an attacker could achieve full administrative control over the affected network device, potentially facilitating lateral movement, interception of traffic, or the injection of malicious routing configurations.",
"technicalDetails": "The vulnerability originates from a deficiency in the authentication logic implemented within the AOS-CX operating system’s remote access stack. The flaw exists where the system fails to properly validate authentication tokens or request state during the initial handshake or session establishment phase, allowing an attacker to bypass the standard credential verification process entirely.\nThe attack flow begins with an unauthenticated actor targeting a network-accessible AOS-CX management interface. By sending a specifically crafted request—likely exploiting a discrepancy between how the authentication module and the underlying transport protocol handle session initialization—the attacker can convince the system that a valid, privileged session has been established.\nOnce the initial request is processed, the system incorrectly transitions the session to an authorized state, granting the actor access to the Command Line Interface (CLI) or the REST API of the switch without the requirement for password or public-key verification.\nThe vulnerable component resides within the session management middleware of the AOS-CX firmware. This component is responsible for mediating user requests and verifying identity before granting access to sensitive system functions. Because this check is bypassed, the subsequent command execution occurs within the context of an administrative user, effectively escalating privileges to the highest level by default.\nThe impact of this post-exploitation behavior is significant. An attacker can execute arbitrary configuration commands, exfiltrate running configurations, modify routing tables, or create new unauthorized administrative accounts to establish persistence. The lack of authentication requirements facilitates automated exploitation attempts, meaning that any AOS-CX switch exposed to an untrusted network segment is at high risk of compromise.\nFurthermore, the vulnerability exposes sensitive information by allowing the attacker to interact with the device's management plane, which often contains credentials or telemetry data that can be used for further network infiltration. The absence of strict session binding in the vulnerable versions allows the attacker to maintain persistence as long as the malicious session remains active, significantly increasing the window of exposure."
}