Arbitrary File Write Vulnerability in AOS-CX by HPE
CVE-2026-73770
7.3HIGH
What is CVE-2026-73770?
An authenticated arbitrary file write vulnerability has been identified in AOS-CX. This flaw could enable a malicious actor, under certain conditions that are outside of their control and requiring a specific action from another user, to create or modify files arbitrarily on the system. Successfully exploiting this vulnerability could allow the attacker to execute commands with elevated privileges on the underlying operating system, posing significant risks to system integrity and security.
Affected Version(s)
AOS-CX 10.18.0000 <= 10.18.0001
AOS-CX 10.18.0000 <= 10.18.0001
AOS-CX 10.17.0000 <= 10.17.1021
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was discovered by internal security research at HPE Networking.
