CVE-2024-54010Low· 3.4▾ SunlitA vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this at…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.
arubaos-cx >= 10.10.0000, < 10.13.1070arubaos-cx >= 10.14.0000, < 10.14.1030arubaos-cx >= 10.15.0000, < 10.15.1000Upgrade past the affected range:
arubaos-cx 10.15.1000Connected by shared product, vendor, weakness, or advisory.
CVE-2025-25040Low· 3.3A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.10…
CVE-2026-73780High· 8.3A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection
CVE-2026-73759Medium· 6.5Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets
CVE-2026-73752High· 8.8An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX
CVE-2026-73749Critical· 9.8Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input
CVE-2026-73751High· 8.8An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.