Cybersecurity

HPE Fixes Critical ArubaOS-CX Vulnerability Enabling Remote Command Execution

HPE has released updates to address a critical vulnerability in ArubaOS-CX that unauthenticated attackers can exploit to execute code with elevated privileges. The security bulletin also covers 23 other vulnerabilities, including issues that could lead to authentication bypass, command execution, and control of network switches.

2026-09-03
3 min read
7 views
فريق تحرير certi.news
HPE Fixes Critical ArubaOS-CX Vulnerability Enabling Remote Command Execution

Hewlett Packard Enterprise (HPE) has released security updates to address a critical vulnerability in the ArubaOS-CX operating system used in enterprise network switches. The vulnerability is tracked as CVE-2026-73749 and consists of a buffer overflow in a service process, allowing a remote, unauthenticated attacker to send specially crafted packets and execute code with elevated privileges.

According to the HPE security bulletin published on September 3, 2026, the issue is associated with several vulnerabilities in a daemon within ArubaOS-CX, caused by improper handling of malformed input. The company strongly recommends that customers upgrade to versions containing the fixes rather than relying solely on mitigations, which the bulletin did not specify.

Affected Versions and Required Updates

  • Version 10.18.0001: Upgrade to 10.18.1002 or later.
  • Version 10.17.1021 and earlier versions: Upgrade to 10.17.1030 or later.
  • Version 10.16.1051 and earlier versions: Upgrade to 10.16.1060 or later.
  • Version 10.13.1180 and earlier versions: Upgrade to 10.13.1190 or later.
  • Version 10.10.1180 and earlier versions: Upgrade to 10.10.1181 or later.

HPE warns that version 10.10.1181 has reached End of Maintenance and generally receives only fixes for critical issues discovered internally by the company. This restriction also applies to CVE-2026-73749, making reliance on this branch over the long term a matter for review in environments that require a regular update and maintenance cycle.

A Broader Range of Vulnerabilities

The bulletin is not limited to the primary critical vulnerability, as it covers 23 other security vulnerabilities, some of which received high severity ratings between 8.1 and 8.8. The listed issues include the possibility of executing commands through the management interface or command-line operations, writing arbitrary files through an API endpoint, executing code with elevated privileges, and a format-string vulnerability in the command-line interface.

The list also includes vulnerabilities that bypass authentication and access-control mechanisms, as well as a vulnerability allowing exploitation of a predictable default password on devices that remain in a factory state or are in the post-ZTP phase before credentials are configured. Other issues include executing JavaScript code in the administrator’s browser through stored XSS and CSRF attacks in some certificate-based sessions.

Why Does This Matter?

ArubaOS-CX is used in the networks of companies, government agencies, universities, healthcare organizations, data centers, and service providers. Therefore, the risk does not concern an isolated endpoint, but rather a management and operating layer that may be connected to the network infrastructure itself. Remediation is a higher priority because the primary vulnerability does not require a valid account, while some of the other vulnerabilities could lead to authentication bypass or administrative privileges.

HPE said that, at the time the bulletin was published, it was not aware of active exploitation of the vulnerabilities or the availability of public proof-of-concept code targeting them. However, the absence of known exploitation does not eliminate the need to identify affected versions and apply the appropriate updates, with particular attention to devices that still use default passwords or branches that have reached End of Maintenance.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news