---
id: CVE-2026-73749
title: >-
  Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for
  improper processing of malformed input
summary: >-
  Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for
  improper processing of malformed input. An unauthenticated remote attacker
  could exploit these vulnerabilities by sending specially crafted packets to
  the affected s…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: hpe
product: arubaos-cx
affected:
  - arubaos-cx < 10.10.1181
  - 'arubaos-cx >= 10.13.0000, < 10.13.1190'
  - 'arubaos-cx >= 10.16.0000, < 10.16.1060'
  - 'arubaos-cx >= 10.17.0000, < 10.17.1030'
  - arubaos-cx = 10.18.0001
patched:
  - arubaos-cx 10.17.1030
published: '2026-09-01'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:55:15.857'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73749'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
epss: 0.00816
epssPercentile: 0.55282
ingestedAt: '2026-09-22T21:11:40.269Z'
---

## Overview

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.

## Affected

- `arubaos-cx < 10.10.1181`
- `arubaos-cx >= 10.13.0000, < 10.13.1190`
- `arubaos-cx >= 10.16.0000, < 10.16.1060`
- `arubaos-cx >= 10.17.0000, < 10.17.1030`
- `arubaos-cx = 10.18.0001`

## Remediation

Upgrade past the affected range:

- `arubaos-cx 10.17.1030`
