---
cve: "CVE-2026-73774"
severity: "HIGH"
cvss: 7.6
epss: "0.3%"
vendor: "Hewlett Packard Enterprise (HPE)"
kev: false
exploited: false
published: "2026-09-01 21:18:44"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-05T18:09:17+02:00"
---

# CVE-2026-73774

> 7.6 HIGH

## Beschreibung

A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in limited disclosure or modification of information and disruption of the affected system.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Hoch | bad |

## BSI-Hinweise (deutsch)

- [Aruba ArubaOS-CX: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3140) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Aruba ArubaOS-CX ausnutzen, um beliebigen Code mit erhöhten/Root-Rechten auszuführen, Sicherheitsmaßnahmen zu umgehen, erhöhte Rechte – einschließlich Administratorzugriff – zu erlangen, Daten offenzulegen oder zu manipulieren, Cross-Site-Scripting durchzuführen oder Denial-of-Service-Zustände zu verursachen.

## Referenzen

- <https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-73774) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
