[Security Vulnerability Alert] HPE Aruba Networking AOS-CX has two major security vulnerabilities.

 
2026/3/19 ~ 2026/9/19
View Count:194

Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Warning TWCERTCC-200-202603-00000017

[Content Description]
HPE recently released a major cybersecurity advisory for Aruba Networking AOS-CX (CVE-2026-23813, CVSS: 9.8 and CVE-2026-23814, CVSS: 8.8).

CVE-2026-23813 exists in the web management interface of the AOS-CX switch and may allow unauthenticated remote attackers to bypass authentication mechanisms, potentially leading to administrator password resets in some cases. CVE-2026-23814 is a command injection vulnerability that may allow authenticated remote attackers with low privileges to inject and execute malicious commands.

[Affected Platforms]
AOS-CX versions 10.17.0001 and below
AOS-CX versions 10.16.1020 and below
AOS-CX versions 10.13.1160 and below
AOS-CX versions 10.10.1170 and below

[Recommended Actions]
Patch the issue according to the solutions released on the official website: https://networkingsupport.hpe.com/home/

Files
None
Top↑