Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Warning TWCERTCC-200-202603-00000017
[Content Description]
HPE recently released a major cybersecurity advisory for Aruba Networking AOS-CX (CVE-2026-23813, CVSS: 9.8 and CVE-2026-23814, CVSS: 8.8).
CVE-2026-23813 exists in the web management interface of the AOS-CX switch and may allow unauthenticated remote attackers to bypass authentication mechanisms, potentially leading to administrator password resets in some cases. CVE-2026-23814 is a command injection vulnerability that may allow authenticated remote attackers with low privileges to inject and execute malicious commands.
[Affected Platforms]
AOS-CX versions 10.17.0001 and below
AOS-CX versions 10.16.1020 and below
AOS-CX versions 10.13.1160 and below
AOS-CX versions 10.10.1170 and below
[Recommended Actions]
Patch the issue according to the solutions released on the official website: https://networkingsupport.hpe.com/home/