Network Security
HPE Issues Critical Firmware Patches for Multiple RCE Vulnerabilities in AOS-CX
Hewlett Packard Enterprise has resolved nearly two dozen critical remote code execution vulnerabilities impacting its AOS-CX network operating system.
Hewlett Packard Enterprise (HPE) has deployed urgent security updates addressing nearly two dozen vulnerabilities affecting its AOS-CX network operating system. Tracked collectively under CVE-2026-73749, this critical issue holds a CVSS score of 9.8, presenting an urgent risk to enterprise networks relying on HPE switching and routing platforms.
Anatomy of the Network Threat
The vulnerability suite enables unauthenticated threat actors to achieve remote code execution (RCE) on impacted networking hardware. Because network switches and core routers manage the transport layer of enterprise communications, a compromised device allows an adversary to monitor traffic, execute man-in-the-middle (MitM) attacks, bypass internal segmentation, and access restricted virtual local area networks (VLANs). Devices with exposed management interfaces are especially susceptible to remote, unauthenticated compromise.
Remediation and Hardening Guidelines
Security teams must prioritize the remediation of enterprise network gear to maintain perimeter and internal segmentation integrity:
- Apply Official Firmware Updates: Upgrade affected AOS-CX hardware to the latest vendor-approved firmware release without delay.
- Isolate Network Management: Ensure all network management planes (SSH, Web UI, SNMP) are restricted to dedicated out-of-band (OOB) management networks.
- Disable Unnecessary Services: Review running switch services and deactivate unused remote configuration protocols.
- Audit Perimeter Access: Verify that network management interfaces are never exposed directly to the public internet.
แหล่งที่มา: SecurityWeek เผยแพร่ครั้งแรก: Fri, 04 Sep 2026 16:11:06 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: SecurityWeek
เผยแพร่ครั้งแรก: Fri, 04 Sep 2026 16:11:06 +0000
บทความต้นฉบับ: https://www.securityweek.com/hpe-patches-critical-rce-vulnerabilities-in-aos-cx/
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
