An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files.
History

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) aos-cx
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) aos-cx

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-22

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to files.
Title Authenticated Path Traversal Vulnerability Leads to Remote Unauthorized Access to Files in AOS-CX
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published: 2026-09-01T20:28:18.139Z

Updated: 2026-09-02T13:53:39.022Z

Reserved: 2026-08-13T16:38:49.644Z

Link: CVE-2026-73760

cve-icon Vulnrichment

Updated: 2026-09-02T13:53:29.413Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T21:18:42.737

Modified: 2026-09-02T19:34:36.770

Link: CVE-2026-73760

cve-icon Redhat

No data.