Hewlett Packard Enterprise (HPE) has taken significant steps to enhance the security of its Aruba Networking ArubaOS-CX (AOS-CX) platform by releasing patches for 34 Common Vulnerabilities and Exposures (CVEs), including critical remote code execution (RCE) flaws. These updates are crucial for maintaining the integrity of enterprise networks.
Details of the Security Patches
In a recent advisory, HPE disclosed that the latest updates address over 150 vulnerabilities across various versions of AOS-CX, such as 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these issues are grouped under individual CVEs for streamlined tracking.
Among the patches, nearly two dozen vulnerabilities are collectively identified as CVE-2026-73749, boasting a critical CVSS score of 9.8. The company has resolved these severe flaws to prevent potential exploitation.
Impact and Risk of Vulnerabilities
The critical security issues originate from the incorrect handling of malformed input directed at an undisclosed service within HPE’s database-focused operating system for enterprise switches. This flaw could allow unauthenticated attackers to send crafted packets to the vulnerable service, leading to RCE with escalated privileges.
The updates also mitigate 22 high-severity CVEs that could result in denial-of-service (DoS), RCE, arbitrary command execution, script code execution in a user’s browser, authentication bypass, privilege escalation, and information disclosure.
Recommendations and Future Outlook
HPE emphasizes that most vulnerabilities were identified by their internal security team, and they have not observed any active exploitation in the wild. To further reduce risk, HPE advises restricting CLI and web-based management interfaces to a dedicated layer 2 segment or VLAN, managed by firewall policies at layer 3 and beyond.
By implementing these patches and recommended security controls, organizations can safeguard their networks against potential threats. HPE continues to prioritize network security and encourages users to apply the updates promptly to mitigate risks.
For further information on related vulnerabilities and updates, readers can explore additional resources on similar issues affecting other platforms such as VMware and Cisco.
