Vulnerability Monitor

The vendors, products, and vulnerabilities you care about
arubaos-cx Vendor: hpe

About This Product

arubaos-cx is a software product offered by hpe. As an operating system, this product forms the foundation of countless systems, making vulnerability monitoring essential for organizations relying on it. Security vulnerabilities in products of this category can affect system availability, data confidentiality, and integrity across entire networks. The significant number of reported vulnerabilities indicates this product has received substantial security scrutiny and community focus over time. Regular assessment of known vulnerabilities and timely patching are fundamental components of responsible system administration for any deployment of this software.

Vulnerability Landscape Summary

SecUtils has identified 55 known vulnerabilities affecting hpe arubaos-cx. This includes 2 critical-severity issues and 35 high-severity issues that warrant immediate attention. Vulnerabilities in this product have been disclosed spanning from 2021 to 2026, indicating a recent active security attention. 18 medium-severity issues complete the vulnerability landscape. Organizations should prioritize patching based on deployment context, asset criticality, and exploitation likelihood rather than severity alone.

Known Vulnerabilities
ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2002-20001 2021-11-11 2026-06-16 7.5 5.0 Likely
CVE-2021-41000 2022-03-02 2026-06-17 8.8 9.0 Likely
CVE-2021-41001 2022-03-02 2026-06-17 8.8 9.0 Likely
CVE-2021-41002 2022-03-02 2026-06-17 8.1 8.5 Likely
CVE-2021-41003 2022-03-02 2026-06-17 6.1 4.3 Likely
CVE-2023-1168 2023-03-22 2026-06-17 7.2 - -
CVE-2023-3718 2023-08-01 2026-06-17 8.8 - -
CVE-2025-37155 2025-11-18 2026-06-17 7.8 - -
CVE-2025-37156 2025-11-18 2026-06-17 6.8 - -
CVE-2025-37157 2025-11-18 2026-06-17 6.7 - -
CVE-2025-37158 2025-11-18 2026-06-17 6.7 - -
CVE-2025-37159 2025-11-18 2026-06-17 5.8 - -
CVE-2025-37160 2025-11-18 2026-06-17 5.3 - -
CVE-2026-23813 2026-03-11 2026-08-11 9.8 - -
CVE-2026-23814 2026-03-11 2026-08-11 8.8 - -
CVE-2026-23815 2026-03-11 2026-08-11 7.2 - -
CVE-2026-23816 2026-03-11 2026-08-11 7.2 - -
CVE-2026-23817 2026-03-11 2026-06-17 6.5 - -
CVE-2026-44880 2026-07-21 2026-08-11 8.8 - -
CVE-2026-63453 2026-07-21 2026-08-11 7.2 - -
CVE-2026-63454 2026-07-21 2026-08-11 7.2 - -
CVE-2026-73749 2026-09-01 2026-09-04 9.8 - -
CVE-2026-73750 2026-09-01 2026-09-15 8.8 - -
CVE-2026-73751 2026-09-01 2026-09-15 8.8 - -
CVE-2026-73752 2026-09-01 2026-09-04 8.8 - -
CVE-2026-73753 2026-09-01 2026-09-10 8.8 - -
CVE-2026-73754 2026-09-01 2026-09-04 5.3 - -
CVE-2026-73755 2026-09-01 2026-09-04 5.7 - -
CVE-2026-73756 2026-09-01 2026-09-04 5.9 - -
CVE-2026-73757 2026-09-01 2026-09-04 6.4 - -
CVE-2026-73758 2026-09-01 2026-09-04 6.5 - -
CVE-2026-73759 2026-09-01 2026-09-04 6.5 - -
CVE-2026-73760 2026-09-01 2026-09-04 6.5 - -
CVE-2026-73761 2026-09-01 2026-09-04 6.5 - -
CVE-2026-73762 2026-09-01 2026-09-04 6.6 - -
CVE-2026-73763 2026-09-01 2026-09-10 7.1 - -
CVE-2026-73764 2026-09-01 2026-09-04 7.1 - -
CVE-2026-73765 2026-09-01 2026-09-04 7.2 - -
CVE-2026-73766 2026-09-01 2026-09-04 7.2 - -
CVE-2026-73767 2026-09-01 2026-09-04 7.2 - -
CVE-2026-73768 2026-09-01 2026-09-04 7.3 - -
CVE-2026-73770 2026-09-01 2026-09-04 7.3 - -
CVE-2026-73771 2026-09-01 2026-09-04 7.5 - -
CVE-2026-73772 2026-09-01 2026-09-04 6.5 - -
CVE-2026-73773 2026-09-01 2026-09-04 7.5 - -
CVE-2026-73774 2026-09-01 2026-09-04 7.6 - -
CVE-2026-73775 2026-09-01 2026-09-04 7.7 - -
CVE-2026-73776 2026-09-01 2026-09-04 7.9 - -
CVE-2026-73777 2026-09-01 2026-09-04 8.1 - -
CVE-2026-73778 2026-09-01 2026-09-10 8.1 - -
CVE-2026-73779 2026-09-01 2026-09-04 8.2 - -
CVE-2026-73780 2026-09-01 2026-09-04 8.3 - -
CVE-2026-73781 2026-09-01 2026-09-04 8.4 - -
CVE-2026-73782 2026-09-01 2026-09-04 8.8 - -
CVE-2026-73783 2026-09-01 2026-09-04 4.9 - -

How SecUtils Interprets Product Data

SecUtils normalizes and enriches National Vulnerability Database (NVD) records for hpe arubaos-cx by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and structuring the data for rapid analysis and asset correlation. For every vulnerability listed, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference information to enable organizations to prioritize patching and risk assessment efficiently. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for vulnerability management and security operations.