AI Security AI安全 6h ago Updated 3h ago 更新于 3小时前 46

HPE Patches Critical RCE Vulnerabilities in AOS-CX HPE修复AOS-CX关键远程代码执行漏洞

HPE released patches addressing 34 CVEs across five AOS-CX versions (10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, 10.10.1181), resolving over 150 individual flaws CVE-2026-73749 (CVSS 9.8) consolidates nearly two dozen critical RCE vulnerabilities allowing unauthenticated remote code execution with elevated privileges 22 high-severity CVEs cover DoS, RCE, arbitrary command/script execution, authentication bypass, privilege escalation, and information disclosure 11 medium-severity CVEs involve HPE为ArubaOS-CX平台发布安全补丁,修复34个CVE漏洞,含关键级远程代码执行(RCE)漏洞 核心漏洞CVE-2026-73749(CVSS 9.8)涉及近24个子问题,源于对畸形输入处理不当 攻击者无需认证即可发送构造数据包实现提权RCE,影响企业交换机管理面 涉及5个软件版本:10.18.1002、10.17.1030、10.16.1060、10.13.1190和10.10.1181 HPE内部安全团队发现多数漏洞,目前未发现野外利用案例

70
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • HPE released patches addressing 34 CVEs across five AOS-CX versions (10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, 10.10.1181), resolving over 150 individual flaws
  • CVE-2026-73749 (CVSS 9.8) consolidates nearly two dozen critical RCE vulnerabilities allowing unauthenticated remote code execution with elevated privileges
  • 22 high-severity CVEs cover DoS, RCE, arbitrary command/script execution, authentication bypass, privilege escalation, and information disclosure
  • 11 medium-severity CVEs involve access control bypass, file reads, DoS, and privilege escalation
  • HPE's security team discovered most flaws internally; no active exploitation in the wild has been reported

Why It Matters

This patch release highlights the persistent security risks in enterprise network infrastructure, particularly database-centric operating systems powering critical switching hardware. The unauthenticated RCE vulnerabilities pose significant threats to organizations relying on ArubaOS-CX for network management, as attackers could gain full control of switch infrastructure without credentials.

Technical Details

  • Affected Versions: AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181
  • Root Cause: Improper processing of malformed input sent to an unnamed service within HPE's database-centric OS for enterprise switches
  • Attack Vector: Unauthenticated attackers can send crafted packets to the vulnerable service, achieving RCE with elevated privileges
  • Vulnerability Distribution: 1 critical (CVE-2026-73749, CVSS 9.8), 22 high-severity, and 11 medium-severity CVEs
  • Mitigation Recommendations: Restrict CLI and web-based management interfaces to dedicated Layer 2 segments/VLANs, enforce firewall policies at Layer 3+, and implement accounting controls for activity tracking and logging

Industry Insight

  • Organizations running ArubaOS-CX should prioritize immediate patching, as unauthenticated RCE in network infrastructure can lead to complete network compromise and lateral movement
  • The consolidation of nearly two dozen issues under a single CVE (CVE-2026-73749) suggests a systemic architectural weakness in input validation that warrants deeper security review of similar database-centric network OS designs
  • Network segmentation and strict access controls for management interfaces should be treated as essential defense-in-depth measures, especially for critical infrastructure components that may not receive timely patches

TL;DR

  • HPE为ArubaOS-CX平台发布安全补丁,修复34个CVE漏洞,含关键级远程代码执行(RCE)漏洞
  • 核心漏洞CVE-2026-73749(CVSS 9.8)涉及近24个子问题,源于对畸形输入处理不当
  • 攻击者无需认证即可发送构造数据包实现提权RCE,影响企业交换机管理面
  • 涉及5个软件版本:10.18.1002、10.17.1030、10.16.1060、10.13.1190和10.10.1181
  • HPE内部安全团队发现多数漏洞,目前未发现野外利用案例

为什么值得看

企业级网络设备的远程代码执行漏洞直接影响数据中心和园区网的安全架构,运维人员需立即评估补丁影响范围。此事件凸显了网络设备管理平面(CLI/Web)作为攻击入口的高风险性,为网络分段和访问控制策略提供了实践参考。

技术解析

  • 漏洞影响范围:34个CVE涵盖关键(1个)、高危(22个)、中危(11个)三个等级,涉及拒绝服务、任意命令执行、浏览器脚本执行、认证绕过、权限提升和信息泄露等多种攻击向量
  • 核心漏洞机制:CVE-2026-73749(CVSS 9.8)由近24个子漏洞聚合而成,根本原因是AOS-CX数据库中心操作系统对未命名服务接收的畸形输入缺乏充分验证
  • 利用条件:未认证攻击者只需向漏洞服务发送构造数据包即可实现远程代码执行并获得高权限,无需任何前置访问权限
  • 修复版本:5个AOS-CX版本分支同步发布补丁,体现企业级网络设备多版本并存的维护现实
  • 缓解建议:HPE建议将CLI和Web管理界面限制在专用二层段/VLAN,或通过三层及以上防火墙策略控制访问,并实施审计日志记录

行业启示

  • 网络设备管理平面的安全加固应作为企业零信任架构的重要组成部分,建议强制实施带外管理(OOB)和微分段策略
  • 厂商内部安全团队的主导发现模式表明,主动安全开发(Shift-Left)和内部红队演练能有效降低漏洞暴露窗口期
  • 企业运维团队需建立网络设备固件/补丁的快速评估和灰度发布流程,以应对关键RCE漏洞的紧急响应需求

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全